CVE-2021-41116 log
Source |
|
Severity | Medium |
Remote | Yes |
Type | Arbitrary command execution |
Description | Windows users running Composer before version 2.1.9 to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-2446 | composer | 2.1.8-1 | 2.1.9-1 | Medium | Not affected |
References |
---|
https://github.com/composer/composer/security/advisories/GHSA-frqg-7g38-6gcf https://github.com/composer/composer/commit/ca5e2f8d505fd3bfac6f7c85b82f2740becbc0aa |