Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-24439

Опубликовано: 06 дек. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.1

Описание

All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments.

РелизСтатусПримечание
bionic

DNE

esm-infra/focal

DNE

focal

DNE

jammy

DNE

kinetic

DNE

trusty

DNE

upstream

needs-triage

xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

3.1.46-1
esm-apps-legacy/xenial

released

1.0.1+git137-gc8b8379-2.1ubuntu0.1~esm1
esm-apps/bionic

released

2.1.8-1ubuntu0.1~esm1
esm-apps/focal

released

3.0.7-1ubuntu0.1~esm1
esm-apps/jammy

released

3.1.24-1ubuntu0.1~esm1
esm-apps/noble

not-affected

esm-apps/resolute

not-affected

esm-apps/xenial

released

1.0.1+git137-gc8b8379-2.1ubuntu0.1~esm1
esm-infra-legacy/trusty

released

0.3.2~RC1-3ubuntu0.1~esm1

Показывать по

EPSS

Процентиль: 92%
0.05378
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
redhat
больше 3 лет назад

All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments.

CVSS3: 8.1
nvd
больше 3 лет назад

All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments.

CVSS3: 8.1
debian
больше 3 лет назад

All versions of package gitpython are vulnerable to Remote Code Execut ...

CVSS3: 8.1
github
больше 3 лет назад

GitPython vulnerable to Remote Code Execution due to improper user input validation

CVSS3: 9.8
fstec
больше 3 лет назад

Уязвимость библиотеки Python для взаимодействия с git-репозиториями gitpython, связанная с неправильной проверкой ввода, позволяющая нарушителю внедрить вредоносный удаленный URL-адрес в команду клонирования

EPSS

Процентиль: 92%
0.05378
Низкий

8.1 High

CVSS3