PT-2024-4387 · Composer+5 · Composer+5

·

CVE-2024-35242

·

Published

2024-06-10

·

Updated

2026-07-17

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Composer versions prior to 2.2.24 and 2.7.7
Description The issue is related to the composer install command running inside a git/hg repository with specially crafted branch names, which can lead to command injection. This requires cloning untrusted repositories.
Recommendations For versions prior to 2.2.24, update to version 2.2.24 for 2.2 LTS. For versions prior to 2.7.7, update to version 2.7.7 for mainline. As a temporary workaround, avoid cloning potentially compromised repositories.

Exploit

Fix

DoS

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04880
BIT-COMPOSER-2024-35242
CVE-2024-35242
DLA-3838-1
DSA-5715-1
DSA-5715-2
GHSA-V9QV-C7WM-WGMF
OPENSUSE-SU-2024:14040-1
OPENSUSE-SU-2024_2106-1
OPENSUSE-SU-2024_2107-1
SUSE-SU-2024:2106-1
SUSE-SU-2024:2107-1
SUSE-SU-2026:1970-1
SUSE-SU-2026:3105-1
USN-7603-1

Affected Products

Astra Linux
Composer
Linuxmint
Red Os
Suse
Ubuntu