Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hcpj-qp55-gfph

Опубликовано: 06 дек. 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.2
CVSS3: 8.1

Описание

GitPython vulnerable to Remote Code Execution due to improper user input validation

All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments.

Ссылки

Пакеты

Наименование

GitPython

pip
Затронутые версииВерсия исправления

<= 3.1.29

3.1.30

EPSS

Процентиль: 99%
0.70543
Высокий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-20
CWE-94

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 3 года назад

All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments.

CVSS3: 9.8
redhat
почти 3 года назад

All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments.

CVSS3: 8.1
nvd
почти 3 года назад

All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments.

CVSS3: 8.1
debian
почти 3 года назад

All versions of package gitpython are vulnerable to Remote Code Execut ...

CVSS3: 9.8
redos
больше 1 года назад

Уязвимость python3-GitPython

EPSS

Процентиль: 99%
0.70543
Высокий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-20
CWE-94