Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45416
HistoryFeb 09, 2024 - 6:59 a.m.

Arbitrary Code Execution

2024-02-0906:59:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
composer
vulnerability
santization
installedversions.php
arbitrary code execution
local privilege escalation

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

7.9

Confidence

High

EPSS

0

Percentile

9.0%

composer is vulnerable to Arbitrary Code Execution. The vulnerability due to improper santization when parsing the installed.php/InstalledVersions.ph file during the invocation of Composer. If Composer is invoked within a directory where InstalledVersions.ph was tampered with by an attacker, arbitrary code execution can occur which may lead to local privilege escalation.

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

7.9

Confidence

High

EPSS

0

Percentile

9.0%