Description
Composer Remote Code Execution vulnerability via web-accessible composer.phar
Impact
Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be impacted if PHP also has register_argc_argv enabled in php.ini.
Patches
2.6.4, 2.2.22 and 1.10.27 patch this vulnerability.
Workarounds
Make sure register_argc_argv is disabled in php.ini, and avoid publishing composer.phar to the web as this really should not happen.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 packagist | | >=0 <1.10.27 || >=2.0.0 <2.2.22 || >=2.3.0 <2.6.4 | 1.10.27, 2.2.22, 2.6.4 |
 debian 11 | | =2.0.11-1 || =2.0.12-1 || =2.0.13-1 || =2.0.14-1 || =2.0.9-2 || =2.0.9-2+deb11u1 || =2.0.9-2+deb11u2 || =2.0.9-2+deb11u3 || =2.0.9-2+deb11u4 || =2.1.10-1 || =2.1.11-1 || =2.1.12-1 || =2.1.14-1 || =2.1.3-1 || =2.1.9-1 || =2.10.0-1 || =2.10.0~rc1-1 || =2.10.0~rc1-2 || =2.10.0~rc1-3 || =2.10.0~rc2-1 || =2.10.1-1 || =2.10.1-2 || =2.10.2-1 || =2.2.0~rc1-1 || =2.2.1-1 || =2.2.1-2 || =2.2.11-1 || =2.2.12-1 || =2.2.13-1 || =2.2.14-1 || =2.2.2-1 || =2.2.3-1 || =2.2.4-1 || =2.2.5-1 || =2.2.6-1 || =2.2.6-2 || =2.2.7-1 || =2.2.9-1 || =2.3.10-1 || =2.3.7-1 || =2.3.7-2 || =2.3.8-1 || =2.3.9-1 || =2.4.0-1 || =2.4.0~rc1-1 || =2.4.1-1 || =2.4.2-1 || =2.4.3-1 || =2.4.4-1 || =2.5.1-1 || =2.5.2-1 || =2.5.3-1 || =2.5.4-1 || =2.5.5-1 || =2.5.6-1 || =2.5.7-1 || =2.5.8-1 || =2.6.2-1 || =2.6.3-1 || =2.6.4-1 || =2.6.5-1 || =2.6.6-1 || =2.7.1-1 || =2.7.1-2 || =2.7.2-1 || =2.7.4-1 || =2.7.6-1 || =2.7.6-2 || =2.7.6-3 || =2.7.7-1 || =2.7.7-2 || =2.7.8-1 || =2.7.9-1 || =2.8.0-1 || =2.8.1-1 || =2.8.10-1 || =2.8.11-1 || =2.8.11-2 || =2.8.12-1 || =2.8.2-1 || =2.8.3-1 || =2.8.4-1 || =2.8.4-2 || =2.8.4-3 || =2.8.5-1 || =2.8.6-1 || =2.8.8-1 || =2.8.9-1 || =2.9.0~rc1-1 || =2.9.1-1 || =2.9.2-1 || =2.9.3-1 || =2.9.4-1 || =2.9.5-1 || =2.9.7-1 || =2.9.8-1 | - |
 debian 12 | | =2.5.5-1 || =2.5.5-1+deb12u1 || =2.5.5-1+deb12u2 || =2.5.5-1+deb12u3 || >=0 <2.5.5-1+deb12u4 | 2.5.5-1+deb12u4 |
 debian 13 | | | 2.6.4-1 |
 debian 14 | | | 2.6.4-1 |