CVE-2022-35241
published 2022-08-04CVE-2022-35241: In versions 2.x before 2.3.1 and all versions of 1.x, when NGINX Instance Manager is in use, undisclosed requests can cause an increase in disk resource…
PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.66%
47.3th percentile
In versions 2.x before 2.3.1 and all versions of 1.x, when NGINX Instance Manager is in use, undisclosed requests can cause an increase in disk resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| composer | composer | >= 0 < 1.0.0~beta2-1ubuntu0.1~esm2 | 1.0.0~beta2-1ubuntu0.1~esm2 |
| composer | composer | >= 0 < 1.6.3-1ubuntu0.1~esm2 | 1.6.3-1ubuntu0.1~esm2 |
| composer | composer | >= 0 < 1.10.1-1ubuntu0.1~esm2 | 1.10.1-1ubuntu0.1~esm2 |
| composer | composer | >= 0 < 2.2.6-2ubuntu4+esm1 | 2.2.6-2ubuntu4+esm1 |
| composer | composer | >= 0 < 2.7.1-2ubuntu0.1~esm1 | 2.7.1-2ubuntu0.1~esm1 |
| f5 | nginx_instance_manager | — | — |
| f5 | nginx_instance_manager | >= 1.0.0 < 1.x* | 1.x* |
| f5 | nginx_instance_manager | 1.0.0 – 1.0.4 | — |
| f5 | nginx_instance_manager | >= 2.0.0 < 2.3.1 | 2.3.1 |
| f5 | nginx_instance_manager | >= 2.x < 2.3.1 | 2.3.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2022-35241: In versions 2
vendor_f5·2022-08-04·CVSS 6.5
CVE-2022-35241 [MEDIUM] CWE-400 CVE-2022-35241: In versions 2
CVE-2022-35241: In versions 2
In versions 2.x before 2.3.1 and all versions of 1.x, when NGINX Instance Manager is in use, undisclosed requests can cause an increase in disk resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: Nginx Instance Manager
Affected Versions: 1.0.0 - 1.0.4; 2.0.0 - 2.3.1
F5 Advisory Articles: K37080719
F5 References: https://support.f5.com/csp/article/K37080719
OSV
composer vulnerabilities
osv·2025-06-30·CVSS 8.8
CVE-2022-24828 composer vulnerabilities
composer vulnerabilities
Thomas Chauchefoin discovered that Composer did not correctly handle
certain arguments. An attacker could possibly use this issue to execute
arbitrary code. This issue only affected Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-24828, CVE-2023-43655)
Ed Cradock discovered that Composer did not correctly handle the exclusion
of certain files. An attacker could possibly use this issue to execute
arbitrary code. This issue only affected Ubuntu 22.04 LTS. (CVE-2024-24821)
Martin Haunschmid discovered that Composer did not correctly handle git
branch names. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2024-35241)
Maciej Piechota discovered that Composer did not correctly handle VCS
branch names. An
GHSA
GHSA-cxjf-pr27-7q48: In versions 2
ghsa_unreviewed·2022-08-05
CVE-2022-35241 [MEDIUM] CWE-400 GHSA-cxjf-pr27-7q48: In versions 2
In versions 2.x before 2.3.1 and all versions of 1.x, when NGINX Instance Manager is in use, undisclosed requests can cause an increase in disk resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-04
Published