SUSE Container Update Advisory: bci/php-apache ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2024:2842-1 Container Tags : bci/php-apache:8 , bci/php-apache:8-24.3 , bci/php-apache:latest Container Release : 24.3 Severity : important Type : security References : 1226181 1226182 CVE-2024-35241 CVE-2024-35242 ----------------------------------------------------------------- The container bci/php-apache was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:2106-1 Released: Thu Jun 20 16:19:01 2024 Summary: Security update for php-composer2 Type: security Severity: important References: 1226181,1226182,CVE-2024-35241,CVE-2024-35242 This update for php-composer2 fixes the following issues: - CVE-2024-35241: Fixed code execution when installing packages in repository with specially crafted branch names (bsc#1226181). - CVE-2024-35242: Fixed command injection via specially crafted branch names during repository cloning (bsc#1226182). The following package changes have been done: - php-composer2-2.2.3-150400.3.12.1 updated - container:sles15-image-15.0.0-36.11.45 updated