Code Injection in composer - CVE-2023-43655

 

Code Injection in composer - CVE-2023-43655

Published: September 29, 2023 / Updated: October 2, 2023


Vulnerability identifier: #VU81296
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-43655
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper access restrictions. A remote attacker can send a specially crafted request to the server with published composer.phar and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system but requires that "register_argc_argv" option is enabled in php.ini.


Affected software

composer
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
Fedora
Web and Scripting Module
openSUSE Leap
Ubuntu
SecurityCenter
snipe-it
composer (Ubuntu package)
composer
php-composer2

How to mitigate CVE-2023-43655

Install updates from vendor's website.

composer - addressed in versions 1.10.27, 2.2.21, 2.6.4
SecurityCenter - update to 6.2.1
snipe-it - update to 6.3.0
composer (Ubuntu package) - addressed in versions 1.0.0~beta2-1ubuntu0.1~esm2, 1.6.3-1ubuntu0.1~esm2, 1.10.1-1ubuntu0.1~esm2, 2.2.6-2ubuntu4+esm1, 2.7.1-2ubuntu0.1~esm1
composer - addressed in versions 1.10.27-1.el7, 2.6.4-1.el9, 2.6.4-1.fc37, 2.6.4-1.fc38, 2.6.4-1.fc39, 2.6.5-1.el9, 2.6.5-1.fc37, 2.6.5-1.fc38, 2.6.5-1.fc39
php-composer2 - update to 2.2.3-150400.3.6.1
composer - update to 2.5.8-2

External References

Related Security Bulletins