Server side template injection In composer/composer
Description
Improper escaping of command arguments on Windows leading to command injection
Impact
Windows users running Composer to install untrusted dependencies are affected and should definitely upgrade for safety. Other OSs and WSL are not affected.
Patches
1.10.23 and 2.1.9 fix the issue
Workarounds
None
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 1.10.23, 2.1.9 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4.