composer/composer is vulnerable to OS Command Injection
77
High Risk
Composer can resolve a package's source through the Perforce p4 command-line client. It does not validate that a Perforce source URL points to a network endpoint before handing it to p4, and the client treats certain address forms as directives to spawn a local helper process such as rsh. A package hosted in a non-Packagist repository can supply a crafted Perforce URL so that arbitrary commands run on the machine performing a source install. The fix restricts Perforce source URLs to network endpoints so they can no longer trigger local command execution.
You are affected if you are using a version that falls within the vulnerable range and you install a package whose source is served from an untrusted Perforce repository.
composer/composer is vulnerable to OS Command Injection in versions 1.0.0 - 2.2.29 and 2.3.0 - 2.10.2.
Upgrade the composer/composer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.