magento-cloud icon indicating copy to clipboard operation
magento-cloud copied to clipboard

Upgrade Composer version to 2.7.7 to address Composer vulnerabilities CVE-2024-35241 and CVE-2024-35242

Open TuVanDev opened this issue 8 months ago • 2 comments

Upgrade Composer version to 2.7.7 to address Composer vulnerabilities CVE-2024-35241 and CVE-2024-35242.

Reference: https://blog.packagist.com/composer-2-7-7/

Nils Adermann, Jun 10, 2024: Today we’re releasing Composer 2.7.7 (PHP 7.2+) and 2.2.24 (LTS for use on PHP 5.3 to 7.1) to address two security vulnerabilities as well as a number of smaller security hardening measures, please update to the new versions immediately (e.g. with composer self-update ).

Description

Fixed Issues (if relevant)

  1. CVE-2024-35241: Command injection via malicious git branch name
  2. CVE-2024-35242: Multiple command injections via malicious git/hg branch names

Manual testing scenarios

  1. ...
  2. ...

Contribution checklist

  • [x] Pull request has a meaningful description of its purpose
  • [x] All commits are accompanied by meaningful commit messages

TuVanDev avatar Jun 15 '24 05:06 TuVanDev