CVE-2022-24439
06.12.2022, 05:15
All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments.Enginsight
| Vendor | Product | Version |
|---|---|---|
| gitpython_project | gitpython | 𝑥 < 3.1.30 |
| debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gitpython |
| ||||||||||||||||||
| python-git |
|
Common Weakness Enumeration
References