CVE-2021-41116Command Injection in Composer

CWE-77Command Injection6 documents5 sources
Severity
9.8CRITICALNVD
CNA8.2
EPSS
1.0%
top 23.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 5

Description

Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

CVEListV5composer/composer< 1.10.23+1
Packagistcomposer/composer2.0.0-alpha12.1.9+1
NVDgetcomposer/composer2.0.02.1.9+1
NVDtenable/tenable.sc< 5.21.0

Patches

🔴Vulnerability Details

4
GHSA
Improper escaping of command arguments on Windows leading to command injection2021-10-05
CVEList
Command injection in composer on Windows2021-10-05
OSV
Improper escaping of command arguments on Windows leading to command injection2021-10-05
OSV
CVE-2021-41116: Composer is an open source dependency manager for the PHP language2021-10-05

📋Vendor Advisories

1
Debian
CVE-2021-41116: composer - Composer is an open source dependency manager for the PHP language. In affected ...2021
CVE-2021-41116 — Command Injection in Composer | cvebase