Описание
GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule names that GitPython processes during submodule initialization, creating attacker-controlled Git repositories at escaped filesystem locations.
EPSS
8.2 High
CVSS3
Дефекты
Связанные уязвимости
(GitPython before 3.1.58 fails to validate submodule names from .gitmod ...)
GitPython before 3.1.58 fails to validate submodule names from .gitmod ...
GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule names that GitPython processes during submodule initialization, creating attacker-controlled Git repositories at escaped filesystem locations.
Уязвимость функции sm_name() файла src/GitPython/git/objects/submodule/util.py библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации
EPSS
8.2 High
CVSS3