Known vulnerabilities in composer (Debian package)

Vendor: Debian
Software CPE: cpe:2.3:o:debian:composer_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 4
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting composer (Debian package) composer (Debian package) is affected by 4 known vulnerabilities: 3 high, 1 low Critical High Medium Low

Vulnerabilities (4)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU91685 - Command injection
CVE-2024-35242
CWE-77 High
No
No
2.0.9-2+deb11u3, 2.5.5-1+deb12u2 11.06.2024 SB2024061107
SB2024061108
SB2024061109
and 6 more
#VU91684 - Command injection
CVE-2024-35241
CWE-77 High
No
No
2.0.9-2+deb11u3, 2.5.5-1+deb12u2 11.06.2024 SB2024061107
SB2024061108
SB2024061109
and 7 more
#VU86276 - Incorrect Default Permissions
CVE-2024-24821
CWE-276 Low
No
No
2.0.9-2+deb11u2, 2.5.5-1+deb12u1 08.02.2024 SB2024020870
SB2024021508
SB2024022241
and 3 more
#VU52777 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-29472
CWE-94 High
No
No
1.8.4-1+deb10u1 30.04.2021 SB2021043007
SB2021043008
SB2021051726
and 3 more