Описание
GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run git, as well as when it runs bash.exe to interpret hooks. If either of those features are used on Windows, a malicious git.exe or bash.exe may be run from an untrusted repository. This issue has been patched in version 3.1.41.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support |
| devel | not-affected | Windows only |
| esm-apps-legacy/xenial | not-affected | Windows only |
| esm-apps/bionic | not-affected | Windows only |
| esm-apps/focal | not-affected | Windows only |
| esm-apps/jammy | not-affected | Windows only |
| esm-apps/noble | not-affected | Windows only |
| esm-apps/resolute | not-affected | Windows only |
| esm-apps/xenial | ignored | end of ESM support, was needs-triage |
| esm-infra-legacy/trusty | not-affected | Windows only |
Показывать по
Ссылки на источники
EPSS
7.8 High
CVSS3
Связанные уязвимости
GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run `git`, as well as when it runs `bash.exe` to interpret hooks. If either of those features are used on Windows, a malicious `git.exe` or `bash.exe` may be run from an untrusted repository. This issue has been patched in version 3.1.41.
GitPython is a python library used to interact with Git repositories. ...
Untrusted search path under some conditions on Windows allows arbitrary code execution
Уязвимость библиотеки Python для взаимодействия с git-репозиториями GitPython, связанная с использованием ненадёжного пути поиска, позволяющая нарушителю выполнить произвольный код с повышенными привилегиями
EPSS
7.8 High
CVSS3