Описание
GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.
An improper input validation vulnerability was found in GitPython. This flaw allows an attacker to inject a maliciously crafted remote URL into the clone command, possibly leading to remote code execution.
Отчет
In Red Hat Openstack, Red Hat Ansible Automation Platform, and Red Hat Certification Program, while the gitpython dependency is present, the affected codebase is not being used. Red Hat Satellite does not use the affected functions during runtime, therefore the possible impact is limited to Moderate.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ansible Automation Platform 1.2 | gitpython | Not affected | ||
Red Hat Ansible Tower 3 | gitpython | Affected | ||
Red Hat Certification for Red Hat Enterprise Linux 6 | redhat-certification-backend | Out of support scope | ||
Red Hat Certification for Red Hat Enterprise Linux 7 | redhat-certification | Out of support scope | ||
Red Hat Certification for Red Hat Enterprise Linux 8 | redhat-certification | Affected | ||
Red Hat Certification for Red Hat Enterprise Linux 9 | redhat-certification | Affected | ||
Red Hat OpenStack Platform 16.1 | GitPython | Fix deferred | ||
Red Hat OpenStack Platform 16.2 | GitPython | Fix deferred | ||
Red Hat OpenStack Platform 17.0 | GitPython | Fix deferred | ||
Red Hat OpenStack Platform 17.1 | GitPython | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
9.8 Critical
CVSS3
Связанные уязвимости
GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.
GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.
GitPython before 3.1.32 does not block insecure non-multi options in c ...
GitPython vulnerable to remote code execution due to insufficient sanitization of input arguments
Уязвимость компонентов clone/clone_from библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю выполнить произвольный код
EPSS
9.8 Critical
CVSS3