CVE-2023-43655
Summary
| CVE | CVE-2023-43655 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-29 20:15:00 UTC |
| Updated | 2024-03-27 10:15:00 UTC |
| Description | Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code execution vulnerability if PHP also has `register_argc_argv` enabled in php.ini. Versions 2.6.4, 2.2.22 and 1.10.27 patch this vulnerability. Users are advised to upgrade. Users unable to upgrade should make sure `register_argc_argv` is disabled in php.ini, and avoid publishing composer.phar to the web as this is not best practice. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 37 Update: composer-2.6.5-1.fc37 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| lists.debian.org/debian-lts-announce/2024/03/msg00030.html |
|
lists.debian.org |
|
| Remote Code Execution via web-accessible composer.phar · Advisory · composer/composer · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 38 Update: composer-2.6.5-1.fc38 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| Merge pull request from GHSA-jm6m-4632-36hf · composer/composer@955a48e · GitHub |
MISC |
github.com |
|
| Merge pull request from GHSA-jm6m-4632-36hf · composer/composer@95e091c · GitHub |
MISC |
github.com |
|
| Merge pull request from GHSA-jm6m-4632-36hf · composer/composer@4fce147 · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 39 Update: composer-2.6.5-1.fc39 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 284632 Fedora Security Update for composer (FEDORA-2023-f3dedfef46)
- 284633 Fedora Security Update for composer (FEDORA-2023-275c12e496)
- 285213 Fedora Security Update for composer (FEDORA-2023-d5ab1f0b44)
- 356522 Amazon Linux Security Advisory for composer : ALAS2023-2023-384
- 503365 Alpine Linux Security Update for composer
- 505995 Alpine Linux Security Update for composer
- 6000547 Debian Security Update for composer (DLA 3777-1)
- 691313 Free Berkeley Software Distribution (FreeBSD) Security Update for Remote Code Execution (RCE) via web (33922b84-5f09-11ee-b63d-0897988a1c07)
- 755066 SUSE Enterprise Linux Security Update for php-composer2 (SUSE-SU-2023:4041-1)
- 995469 PHP (Composer) Security Update for composer/composer (GHSA-jm6m-4632-36hf)