CVE-2023-40267OS Command Injection in Project Gitpython

Severity
9.8CRITICALNVD
EPSS
0.4%
top 42.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 11
Latest updateAug 31

Description

GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

debiandebian/python-git< python-git 3.1.30-1+deb12u2 (bookworm)

Patches

🔴Vulnerability Details

3
OSV
GitPython vulnerable to remote code execution due to insufficient sanitization of input arguments2023-08-11
GHSA
GitPython vulnerable to remote code execution due to insufficient sanitization of input arguments2023-08-11
OSV
CVE-2023-40267: GitPython before 32023-08-11

📋Vendor Advisories

3
Ubuntu
GitPython vulnerability2023-08-31
Red Hat
GitPython: Insecure non-multi options in clone and clone_from is not blocked2023-08-11
Debian
CVE-2023-40267: python-git - GitPython before 3.1.32 does not block insecure non-multi options in clone and c...2023