Source |
SecurityWeek |
Identifiant |
7297320 |
Date de publication |
2022-10-04 15:14:58 (vue: 2022-10-04 18:07:14) |
Titre |
Critical Packagist Vulnerability Opened Door for PHP Supply Chain Attack |
Texte |
Code security company SonarSource today published details on a severe vulnerability impacting Packagist, which could have been abused to mount supply chain attacks targeting the PHP community.
|
Notes |
|
Envoyé |
Oui |
Condensat |
abused attack attacks been chain code community company could critical details door have impacting mount opened packagist php published security severe sonarsource supply targeting today vulnerability which |
Tags |
Vulnerability
|
Stories |
|
Move |
|
Src |
Date (GMT) |
Titre |
Description |
Tags |
Stories |
Notes |
 |
2022-10-07 10:41:18 |
(Déjà vu) Comment: Critical Packagist Vulnerability Opened Door for PHP Supply Chain Attack (lien direct) |
Code security company SonarSource has published details on a severe vulnerability impacting Packagist, which could have been abused to mount supply chain attacks targeting the PHP community. Packagist is the default repository for PHP dependency manager Composer, aggregating public PHP packages that can be installed using Composer. Each month, Composer is used to download more than […] |
Vulnerability
|
|
|