-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from insufficient cache key uniqueness when storing dist packages. The key components (package name, dist type, repository-provided reference) could be replicated across projects, as attackers could predict/fabricate commit hashes. The Package::getDistReference provided the vulnerable reference value, while FileDownloader::getCacheKey used these values to create non-unique cache keys. The fix in 1.0.0 likely added project-specific context (like repository URLs) to the cache key generation.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| composer/composer | composer | <= 1.0.0-alpha11 | 1.0.0 |
KEV Misses 88% of Exploited CVEs- Get the report