96 lines
4.2 KiB
JSON
Raw Normal View History

{
"id": "CVE-2024-35241",
"sourceIdentifier": "security-advisories@github.com",
"published": "2024-06-10T22:15:09.677",
"lastModified": "2025-02-13T18:18:05.763",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code. Patches for this issue are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting."
},
{
"lang": "es",
"value": "Composer es un administrador de dependencias para PHP. En la rama 2.x anterior a las versiones 2.2.24 y 2.7.7, los comandos `status`, `reinstall` y `remove` con paquetes instalados desde el c\u00f3digo fuente a trav\u00e9s de git que contienen nombres de ramas especialmente manipulados en el repositorio se pueden usar para ejecutar c\u00f3digo. Los parches para este problema est\u00e1n disponibles en la versi\u00f3n 2.2.24 para 2.2 LTS o 2.7.7 para la l\u00ednea principal. Como workaround, evite instalar dependencias a trav\u00e9s de git usando `--prefer-dist` o la configuraci\u00f3n de configuraci\u00f3n `preferred-install: dist`."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security-advisories@github.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "security-advisories@github.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-77"
}
]
}
],
"references": [
{
"url": "https://github.com/composer/composer/commit/b93fc6ca437da35ae73d667d0618749c763b67d4",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/composer/composer/commit/ee28354ca8d33c15949ad7de2ce6656ba3f68704",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/composer/composer/security/advisories/GHSA-47f6-5gq3-vx9c",
"source": "security-advisories@github.com"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PO4MU2BC7VR6LMHEX4X7DKGHVFXZV2MC/",
"source": "security-advisories@github.com"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VLPJHM2WWSYU2F6KHW2BYFGYL4IGTKHC/",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/composer/composer/commit/b93fc6ca437da35ae73d667d0618749c763b67d4",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/composer/composer/commit/ee28354ca8d33c15949ad7de2ce6656ba3f68704",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/composer/composer/security/advisories/GHSA-47f6-5gq3-vx9c",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PO4MU2BC7VR6LMHEX4X7DKGHVFXZV2MC/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VLPJHM2WWSYU2F6KHW2BYFGYL4IGTKHC/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}