HIGH8.8CVE-2024-35241Composer vulnerable to command injection via malicious git branch name >= 2.0.0, < 2.2.24, >= 2.3.0, < 2.7.7
HIGH8.8CVE-2024-35242Composer vulnerable to command injection via malicious git/hg branch names >= 2.0.0, < 2.2.24, >= 2.3.0, < 2.7.7
HIGH8.8CVE-2024-24821Code execution and possible privilege escalation via compromised InstalledVersions.php or installed.php in Composer >= 2.0.0, < 2.2.23, >= 2.3.0, < 2.7.0
HIGH8.8Remote Code Execution via web-accessible composer.phar
from 0, < 1.10.27, >= 2.0.0, < 2.2.21, >= 2.3.0, < 2.6.4
HIGH8.3Missing input validation can lead to command execution in composer
from 0, < 1.10.26, >= 2.0.0, < 2.2.12, >= 2.3.0, < 2.3.5
HIGH7.5Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs
>= 1.0.0, < 1.10.28, >= 2.0.0, < 2.2.28, >= 2.3.0, < 2.9.8
HIGH7.0Composer: Arbitrary file write outside vendor via malicious transitive package name
>= 1.0.0, < 2.2.29, >= 2.3.0, < 2.10.2
MEDIUM6.1Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
>= 1.0.0, < 2.2.29, >= 2.3.0, < 2.10.2
MEDIUM4.7Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
>= 1.0.0, < 2.2.29, >= 2.3.0, < 2.10.2
MEDIUM4.3Composer vulnerable to ANSI sequence injection
>= 2.0.0, < 2.2.26, >= 2.3.0, < 2.9.3