CVE-2023-43655 is a remote code execution vulnerability affecting Composer, a PHP dependency manager, specifically versions prior to 2.6.4, 2.2.22, and 1.10.27. This flaw occurs when a composer.phar file is publicly accessible on a web server and PHP's register_argc_argv setting is enabled, impacting various Debian and Fedora distributions. With a CVSS score of 8.8 (High), this vulnerability is easily exploitable over the network with low privileges and no user interaction, potentially leading to complete compromise of confidentiality, integrity, and availability. The FAUCET Risk Score is 72/100, indicating significant risk. There is currently no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, suggesting low public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.10.27CPE matchmatch criteria | cpe:2.3:a:getcomposer:composer:*:*:*:*:*:*:*:* | ||
>= 2.0.0, < 2.2.21CPE matchmatch criteria | cpe:2.3:a:getcomposer:composer:*:*:*:*:*:*:*:* | ||
>= 2.3.0, < 2.6.4CPE matchmatch criteria | cpe:2.3:a:getcomposer:composer:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.