GHSA-frqg-7g38-6gcf
Dashboard / Vulnerabilities / GHSA-frqg-7g38-6gcf
GHSA-frqg-7g38-6gcf
Summary: Improper escaping of command arguments on Windows leading to command injection
Details: ### Impact Windows users running Composer to install untrusted dependencies are affected and should definitely upgrade for safety. Other OSs and WSL are not affected. ### Patches 1.10.23 and 2.1.9 fix the issue ### Workarounds None
References: https://github.com/composer/composer/security/advisories/GHSA-frqg-7g38-6gcf, https://nvd.nist.gov/vuln/detail/CVE-2021-41116, https://github.com/composer/composer/commit/ca5e2f8d505fd3bfac6f7c85b82f2740becbc0aa, https://github.com/FriendsOfPHP/security-advisories/blob/master/composer/composer/CVE-2021-41116.yaml, https://github.com/composer/composer, https://www.sonarsource.com/blog/securing-developer-tools-package-managers, https://www.tenable.com/security/tns-2022-09
Affected packages
Package
Name: composer/composer
Purl: pkg:composer/composer/composer
Affected ranges
Type: ECOSYSTEM
Events:
