CVE-2021-29472 is a critical vulnerability in Composer, a PHP dependency manager, affecting versions 1.10.22 and 2.0.13 and earlier. It allows remote code execution (RCE) due to improper sanitization of Mercurial repository URLs in composer.json files and package source download URLs, impacting services like Packagist.org. With a CVSS score of 8.8 (HIGH), it presents a significant risk (FAUCET Risk Score 75/100) as an unauthenticated attacker could achieve full compromise (C:H, I:H, A:H) with low attack complexity. Although patched on Packagist.org and Private Packagist and not observed to be actively exploited, the vulnerability has garnered community attention, including a Reddit discussion and media coverage, indicating its potential for future exploitation. No public exploit code or Metasploit modules are currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.10.22CPE matchmatch criteria | cpe:2.3:a:getcomposer:composer:*:*:*:*:*:*:*:* | ||
>= 2.0, < 2.0.13CPE matchmatch criteria | cpe:2.3:a:getcomposer:composer:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.