Security update composer/composer (CVE-2023-43655)

Created on 14 February 2024, 10 months ago
Updated 28 February 2024, 10 months ago

Problem/Motivation

Cover-My-Behind Disclaimer:
Discussed this with @longwave from the Security Team and this CVE was found suitable to be handled in public.

https://github.com/advisories/GHSA-7c6p-848j-wh5h
https://www.cve.org/CVERecord?id=CVE-2024-24821

Steps to reproduce

$ composer audit
Found 1 security vulnerability advisory affecting 1 package:
+-------------------+------------------------------------------------------------------------+
| Package           | composer/composer                                                                |
| CVE               | CVE-2024-24821                                                                   |
| Title             | Composer code execution and possible privilege escalation via compromised        |
|                   | InstalledVersions.php or installed.php                                           |
| URL               | https://github.com/advisories/GHSA-7c6p-848j-wh5h                                |
| Affected versions | >=2.3.0-rc1,<2.7.0|>=2.0.0-alpha1,<2.2.23                                        |
| Reported at       | 2024-02-08T15:06:38+00:00                                                        |
+-------------------+----------------------------------------------------------------------------------+

Proposed resolution

Update composer/composer to latest and bump the version constraint in composer.json to ^2.7.

Remaining tasks

User interface changes

API changes

Data model changes

Release notes snippet

πŸ“Œ Task
Status

Fixed

Version

10.1 ✨

Component
ComposerΒ  β†’

Last updated 3 days ago

No maintainer
Created by

πŸ‡³πŸ‡±Netherlands spokje

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Merge Requests

Comments & Activities

Production build 0.71.5 2024