CVE-2022-24439
06.12.2022, 05:15
All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments.Enginsight
Vendor | Product | Version |
---|---|---|
gitpython_project | gitpython | 𝑥 < 3.1.30 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
gitpython |
| ||||||||||||||||||
python-git |
|
Common Weakness Enumeration
References