Fedora 42 : composer (2026-13b4dbe546)

medium Nessus Plugin ID 283686

Synopsis

The remote Fedora host is missing one or more security updates.

Description

The remote Fedora 42 host has a package installed that is affected by a vulnerability as referenced in the FEDORA-2026-13b4dbe546 advisory.

### Version 2.9.3 - 2025-12-30

* Security: Fixed ANSI sequence injection (GHSA-59pp-r3rg-353g / CVE-2025-67746)
* Fixed `COMPOSER_NO_SECURITY_BLOCKING` env var not being respected for `updates` done via the `install` command, and added `--no-security-blocking` flag to `install` as well (#12677)
* Fixed `update --lock` / `update mirrors` not working when locked packages contain vulnerabilities (#12645)
* Fixed `client-certificate` authentication implementation (#12667)
* Fixed `php-ext` schema not being validated in ValidatingArrayLoader (#12694)
* Fixed crash when `--bump-after-update` is used and the lock file is disabled (#12660)
* Fixed support for SecureTransport + LibreSSL on macOS (#12615)
* Fixed display of reasons for why advisories are ignored (#12668)
* Fixed compatibility issues when git has log.showSignature enabled (#12666)
* Fixed curl downloader not retrying when a timeout (err 28) failure occurs (#12662)
* Fixed EventDispatcher requiring a full Composer instance to function (#12629)



Tenable has extracted the preceding description block directly from the Fedora security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected composer package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2026-13b4dbe546

Plugin Details

Severity: Medium

ID: 283686

File Name: fedora_2026-13b4dbe546.nasl

Version: 1.1

Type: local

Agent: unix

Published: 1/14/2026

Updated: 1/14/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.0

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2025-67746

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 5.3

Threat Score: 1.3

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:composer, cpe:/o:fedoraproject:fedora:42

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 1/5/2026

Vulnerability Publication Date: 12/30/2025

Reference Information

CVE: CVE-2025-67746