Code Injection in composer - CVE-2023-43655
Published: September 29, 2023 / Updated: October 2, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper access restrictions. A remote attacker can send a specially crafted request to the server with published composer.phar and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system but requires that "register_argc_argv" option is enabled in php.ini.
Affected software
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
Fedora
Web and Scripting Module
openSUSE Leap
Ubuntu
SecurityCenter
snipe-it
composer (Ubuntu package)
composer
php-composer2
How to mitigate CVE-2023-43655
SecurityCenter - update to 6.2.1
snipe-it - update to 6.3.0
composer (Ubuntu package) - addressed in versions 1.0.0~beta2-1ubuntu0.1~esm2, 1.6.3-1ubuntu0.1~esm2, 1.10.1-1ubuntu0.1~esm2, 2.2.6-2ubuntu4+esm1, 2.7.1-2ubuntu0.1~esm1
composer - addressed in versions 1.10.27-1.el7, 2.6.4-1.el9, 2.6.4-1.fc37, 2.6.4-1.fc38, 2.6.4-1.fc39, 2.6.5-1.el9, 2.6.5-1.fc37, 2.6.5-1.fc38, 2.6.5-1.fc39
php-composer2 - update to 2.2.3-150400.3.6.1
composer - update to 2.5.8-2
External References
Related Security Bulletins
- Remote code execution in composer.phar
- Fedora 38 update for composer
- Fedora 39 update for composer
- Fedora EPEL 9 update for composer
- Fedora 37 update for composer
- Fedora EPEL 7 update for composer
- Fedora EPEL 9 update for composer
- Fedora 37 update for composer
- Fedora 39 update for composer
- Fedora 38 update for composer
- SUSE update for php-composer2
- Multiple vulnerabilities in Tenable Security Center
- Multiple vulnerabilities in snipe-it
- Amazon Linux AMI update for composer
- Ubuntu update for composer
- Gentoo update for Composer