Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities BSI Germany

[NEU] [mittel] Composer: Mehrere Schwachstellen

Multiple vulnerabilities in Composer, an open-source PHP dependency manager, allow an attacker to bypass security mechanisms, write arbitrary files, or disclose information, though exploitation may require specific configurations and is not a remote attack. The CVSS Base Score is 7.0 (High). Affected versions are Composer prior to 2.2.29 and prior to 2.10.2, with patches available in those respective versions.
Read Full Article →

[WID-SEC-2026-2235] Composer: Mehrere Schwachstellen CVSS Base Score 7.0 (hoch) CVSS Temporal Score 6.1 (mittel) Remoteangriff nein Datum 07.07.2026 Stand 08.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux UNIX Windows Produktbeschreibung Composer ist ein Open-Source-Abhängigkeitsmanager für PHP-Projekte. Produkte 07.07.2026 Open Source Composer <2.2.29 Open Source Composer <2.10.2 Angriff Angriff Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Composer ausnutzen, um Sicherheitsmechanismen zu umgehen, um beliebige Dateien zu schreiben oder um Informationen offenzulegen. Zur erfolgreichen Ausnutzung sind teilweise bestimmte Konfigurationen erforderlich. CVE Informationen Versionshistorie Feedback zum Advisory geben

Share this article