CVE-2021-29472
HighAdvisory
Published 29 Apr 2021In the index since 8 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.8
- base score, highest
- EPSS
- 0.047
- 91st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3
- of 17,781 indexed, latest versions
- Container images
- 1
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Composer's missing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with Mercurial
Carried by container images the latest versions of 3 of 17,781 indexed charts deploy, on 1 image.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| composer/ | 1.7.0 | 1.10.22 | 1 |
- OSV records
- GHSA-h5h8-pc6h-jvvx
- Also known as
- BIT-composer-2021-29472
Charts affected
3 by stars
Container images carrying it
1 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| anapsix/ | fae78e3809e9 | composer/ | 1.10.22 | 3 |