Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 6.1epss 0.2%
probabilidade de exploração
0.2%top 93% das CVEs
exploração observada
nãonenhuma fonte reporta
Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer's binary installation flow to chmod an existing host file to a world-readable and world-executable mode during composer install, update, or require. This issue is fixed in versions 2.2.29 and 2.10.2.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Produtos afetados
composer · composerReferências
https://github.com/composer/composer/commit/502c6c4f699802d9cf464728b3e8a95674f919a0https://github.com/composer/composer/commit/c50b1efd13ebd73f6dca19b31424c5a02bf93cc1https://github.com/composer/composer/releases/tag/2.10.2https://github.com/composer/composer/releases/tag/2.2.29https://github.com/composer/composer/security/advisories/GHSA-gjfg-22fp-rrxx