Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1nM2o1LW1wcDItMmZxbc4AAxJJ
symfont/process typosquatting malware spoofs symfony/process
In September 2021, security researchers discovered a malicious Composer package called symfont/process
, a typosquat targeting users of symfony/process
. The malicious package has since been removed from Packagist.
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nM2o1LW1wcDItMmZxbc4AAxJJ
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 2 years ago
Updated: almost 2 years ago
Identifiers: GHSA-g3j5-mpp2-2fqm
References:
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfont/process/2021-09-10.yaml
- https://www.kernelmode.blog/typosquatting-malware-found-in-composer-repository/
- https://github.com/advisories/GHSA-g3j5-mpp2-2fqm
Affected Packages
packagist:symfont/process
Affected Version Ranges: >= 0No known fixed version