Known vulnerabilities in composer 1.0.0beta1
Vendor:
getcomposer.org
Software:
composer
Version:
1.0.0beta1
Software CPE:
cpe:2.3:a:getcomposer.org:composer:*:*:*:*:*:*:*:*
Website:
https://getcomposer.org
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
2.2.30
2.10.3
2.2.29
2.10.2
2.10.1
2.10.0
1.10.28
2.2.28
2.9.8
2.9.7
2.2.27
2.9.6
2.9.5
2.9.4
2.9.3
2.2.26
2.9.2
2.9.1
2.9.0
2.8.12
2.8.11
2.8.10
2.8.9
2.8.8
2.8.7
2.8.6
2.8.5
2.8.4
2.2.25
2.8.3
2.8.2
2.8.1
2.8.0
2.7.9
2.7.8
2.7.7
2.2.24
2.7.6
2.7.5
2.7.4
2.7.3
2.7.2
2.7.1
2.7.0
2.2.23
2.6.6
2.6.5
2.6.4
2.2.22
1.10.27
2.6.3
2.6.2
2.6.1
2.6.0
2.5.8
2.5.7
2.5.6
2.5.5
2.5.4
2.2.21
2.2.20
2.5.3
2.5.2
2.2.19
2.5.1
2.5.0
2.4.4
2.4.3
2.4.2
2.4.1
2.2.18
2.4.0
2.3.10
2.2.17
2.3.9
2.2.16
2.3.8
2.2.15
2.3.7
2.2.14
2.3.6
2.2.13
2.3.5
2.2.12
1.10.26
2.3.4
2.3.3
2.2.11
2.3.2
2.3.1
2.3.0
2.2.10
2.2.9
2.2.8
2.2.7
2.2.6
2.2.5
1.10.25
2.2.4
2.2.3
2.2.2
2.2.1
2.2.0
1.10.24
2.1.14
2.1.12
2.1.11
2.1.10
1.10.23
2.1.9
2.1.8
2.1.7
2.1.6
2.1.5
2.1.4
2.1.3
2.1.2
2.1.1
2.1.0
2.0.14
2.0.5
2.0.0
1.10.22
1.10.21
1.10.20
1.10.18
1.10.14
1.10.12
1.10.11
1.10.2
1.8.2
1.8.1
1.7.1
1.7.0
1.6.4
1.6.1
1.6.0
1.5.4
1.5.3
1.4.3
1.4.1
1.4.0
1.3.3
1.3.2
1.3.1
1.3.0
1.2.4
1.2.3
1.2.2
1.1.3
1.1.1
1.1.0
1.0.3
1.0.1
2.0.13
2.0.12
2.0.10
2.0.11
2.0.9
2.0.8
1.10.19
2.0.7
2.0.6
1.10.17
2.0.4
2.0.3
1.10.16
2.0.2
2.0.1
1.0.2
1.0.0
1.0.0beta1
1.2.1
1.2.0
1.1.2
1.5.1
1.5.0
1.4.2
1.10.15
1.10.1
1.10.13
1.6.3
1.6.2
1.5.6
1.5.5
1.8.0
1.7.3
1.7.2
1.8.5
1.8.4
1.8.3
1.9.0
1.10.5
1.10.4
1.10.3
1.10.0
1.9.3
1.9.2
1.10.9
1.10.10
1.10.8
1.5.2
1.10.7
1.10.6
1.9.1
1.8.6
1.6.5
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU81296 - Improper Control of Generation of Code ('Code Injection') CVE-2023-43655 |
CWE-94 | High | 1.10.27, 2.2.21, 2.6.4 | 29.09.2023 |
SB2023092947 SB2023092956 SB2023092957 and 13 more |
||
| #VU62312 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2022-24828 |
CWE-78 | High | 1.10.26, 2.2.12, 2.3.5 | 14.04.2022 |
SB2022041401 SB2022042017 SB2022090517 and 7 more |
||
| #VU52777 - Improper Control of Generation of Code ('Code Injection') CVE-2021-29472 |
CWE-94 | High | 1.10.22, 2.0.13 | 30.04.2021 |
SB2021043007 SB2021043008 SB2021051726 and 3 more |