GHSA-jm6m-4632-36hf

    Dashboard / Vulnerabilities / GHSA-jm6m-4632-36hf

    GHSA-jm6m-4632-36hf

    Published: 29 Sept 2023Last Modified: 13 Feb 2025

    Summary: Composer Remote Code Execution vulnerability via web-accessible composer.phar

    Details: ### Impact Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be impacted if PHP also has `register_argc_argv` enabled in php.ini. ### Patches 2.6.4, 2.2.22 and 1.10.27 patch this vulnerability. ### Workarounds Make sure `register_argc_argv` is disabled in php.ini, and avoid publishing composer.phar to the web as this really should not happen.

    Affected packages

    Package

    Name: composer/composer

    Purl: pkg:composer/composer/composer

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.10.27

    Affected versions

    1.0.0
    1.0.0-alpha1
    1.0.0-alpha10
    1.0.0-alpha11
    1.0.0-alpha2
    1.0.0-alpha3
    1.0.0-alpha4
    1.0.0-alpha5
    1.0.0-alpha6
    1.0.0-alpha7
    1.0.0-alpha8
    1.0.0-alpha9
    1.0.0-beta1
    1.0.0-beta2
    1.0.1
    1.0.2
    1.0.3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-jm6m-4632-36hf | CVE-DB