CVE Feed

    Dashboard / CVE / CVE-2024-35242

    CVE-2024-35242

    Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. This requires cloning untrusted repositories. Patches are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid cloning potentially compromised repositories.

    Published:Jun 10, 2024
    Last Modified:Apr 15, 2026
    EPS:Jun 10, 2024
    EPSS Score:0.23787
    CVSS Score:8.8

    Affected Products

    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Getcomposer
    Product
    Composer

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High