StackRadar

CVE-2023-43655

High

Advisory

Published 29 Sept 2023In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
6
deployed by those charts
Fix available
1 of 1
affected package

Composer Remote Code Execution vulnerability via web-accessible composer.phar

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 6 images.

Affected packageAffected versionsFixed inImages
composer/composercomposer1.7.0, 1.10.24, 2.1.11, 2.1.14+1 more1.10.27, 2.2.226
OSV records
GHSA-jm6m-4632-36hf
Also known as
BIT-composer-2023-43655

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
mauticone-acre-fundVerified publisher0.1.71 of 3See more

mautic one-acre-fund 0.1.7

1 of the 3 container images this version deploys carry CVE-2023-43655.

Container imageDigestPackageFixed in
mautic/mautic:v4-apache94ea4acf4049
composer/composer@2.2.12
2.2.22

Open the chart page →

2,667
repmanszpadel-chartsVerified publisher3.52.171 of 3See more

repman szpadel-charts 3.52.17

1 of the 3 container images this version deploys carry CVE-2023-43655.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
composer/composer@1.10.24
1.10.27

Open the chart page →

7,052
repmanrepman-helmchartVerified publisher1.0.121 of 3See more

repman repman-helmchart 1.0.12

1 of the 3 container images this version deploys carry CVE-2023-43655.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
composer/composer@1.10.24
1.10.27

Open the chart page →

3,596
satisfyanapsixVerified publisher1.1.31 of 1See more

satisfy anapsix 1.1.3

1 of the 1 container images this version deploys carry CVE-2023-43655.

Container imageDigestPackageFixed in
anapsix/satisfydigest-pinnedfae78e3809e9
composer/composer@1.7.0
1.10.27

Open the chart page →

1,572
satisfycloudnativeapp1.0.01 of 1See more

satisfy cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-43655.

Container imageDigestPackageFixed in
anapsix/satisfydigest-pinnedfae78e3809e9
composer/composer@1.7.0
1.10.27

Open the chart page →

1,572
bookstackgeek-cookbookVerified publisher5.2.01 of 1See more

bookstack geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2023-43655.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v21.12f05447347ff1
composer/composer@2.1.14
2.2.22

Open the chart page →

1,269
shopwarerobjuz2.0.01 of 6See more

shopware robjuz 2.0.0

1 of the 6 container images this version deploys carry CVE-2023-43655.

Container imageDigestPackageFixed in
shyim/shopware:6.4.6.0a951c0e6b836
composer/composer@2.1.11
2.2.22

Open the chart page →

2,972
bookstackschmitzis0.1.11 of 1See more

bookstack schmitzis 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-43655.

Container imageDigestPackageFixed in
solidnerd/bookstack:21.12762ffd5c51d3
composer/composer@2.1.14
2.2.22

Open the chart page →

2,751
repmanteam-blueVerified publisher0.3.01 of 5See more

repman team-blue 0.3.0

1 of the 5 container images this version deploys carry CVE-2023-43655.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
composer/composer@1.10.24
1.10.27

Open the chart page →

3,993
satisfyymrs1.0.21 of 1See more

satisfy ymrs 1.0.2

1 of the 1 container images this version deploys carry CVE-2023-43655.

Container imageDigestPackageFixed in
anapsix/satisfydigest-pinnedfae78e3809e9
composer/composer@1.7.0
1.10.27

Open the chart page →

1,572

Container images carrying it

6 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
anapsix/satisfyfae78e3809e9
composer/composer@1.7.0
1.10.27
3
buddy/repman:1.4.0097c897f8b54
composer/composer@1.10.24
1.10.27
3
mautic/mautic:v4-apache94ea4acf4049
composer/composer@2.2.12
2.2.22
1
shyim/shopware:6.4.6.0a951c0e6b836
composer/composer@2.1.11
2.2.22
1
solidnerd/bookstack:21.12762ffd5c51d3
composer/composer@2.1.14
2.2.22
1
ghcr.io/linuxserver/bookstack:version-v21.12f05447347ff1
composer/composer@2.1.14
2.2.22
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.