CVE-2021-41116 log
| Source |
|
| Severity | Medium |
| Remote | Yes |
| Type | Arbitrary command execution |
| Description | Windows users running Composer before version 2.1.9 to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-2446 | composer | 2.1.8-1 | 2.1.9-1 | Medium | Not affected |
| References |
|---|
https://github.com/composer/composer/security/advisories/GHSA-frqg-7g38-6gcf https://github.com/composer/composer/commit/ca5e2f8d505fd3bfac6f7c85b82f2740becbc0aa |