Lucene search

K
osvGoogleOSV:GHSA-X7CR-6QR6-2HH6
HistoryApr 22, 2022 - 8:15 p.m.

Missing input validation can lead to command execution in composer

2022-04-2220:15:38
Google
osv.dev
28
composer
vcsdriver
command execution
vulnerability
packagist
private packagist
input validation
mercurial
git

EPSS

0.003

Percentile

65.3%

The Composer method VcsDriver::getFileContent() with user-controlled $file or $identifier arguments is susceptible to an argument injection vulnerability. It can be leveraged to gain arbitrary command execution if the Mercurial or the Git driver are used.

This led to a vulnerability on Packagist.org and Private Packagist, i.e., using the composer.json readme field as a vector for injecting parameters into the $file argument for the Mercurial driver or via the $identifier argument for the Git and Mercurial drivers.

Composer itself can be attacked through branch names by anyone controlling a Git or Mercurial repository, which is explicitly listed by URL in a project’s composer.json.

To the best of our knowledge, this was not actively exploited. The vulnerability has been patched on Packagist.org and Private Packagist within a day of the vulnerability report.