Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4j5j-58j7-6c3w

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Dulwich Arbitrary code execution via commit with directory path starting with .git

The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a commit with a directory path starting with .git/, which is not properly handled when checking out a working tree.

Пакеты

Наименование

dulwich

pip
Затронутые версииВерсия исправления

< 0.9.9

0.9.9

EPSS

Процентиль: 86%
0.02765
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Связанные уязвимости

ubuntu
почти 11 лет назад

The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a commit with a directory path starting with .git/, which is not properly handled when checking out a working tree.

nvd
почти 11 лет назад

The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a commit with a directory path starting with .git/, which is not properly handled when checking out a working tree.

debian
почти 11 лет назад

The build_index_from_tree function in index.py in Dulwich before 0.9.9 ...

EPSS

Процентиль: 86%
0.02765
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3