Improper escaping of command arguments on Windows leading to command injection
Package
Affected versions
< 1.10.23
>= 2.0.0-alpha1, < 2.1.9
Patched versions
1.10.23
2.1.9
Description
Published by the National Vulnerability Database
Oct 5, 2021
Reviewed
Oct 5, 2021
Published to the GitHub Advisory Database
Oct 5, 2021
Last updated
Feb 5, 2024
Impact
Windows users running Composer to install untrusted dependencies are affected and should definitely upgrade for safety. Other OSs and WSL are not affected.
Patches
1.10.23 and 2.1.9 fix the issue
Workarounds
None
References