CVE-2022-24439
Summary
| CVE | CVE-2022-24439 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-06 05:15:00 UTC |
| Updated | 2024-01-09 03:21:00 UTC |
| Description | All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 38 Update: GitPython-3.1.32-1.fc38 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] [DLA 3502-1] python-git security update |
MLIST |
lists.debian.org |
|
| GitPython: Code Execution via Crafted Input (GLSA 202311-01) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 37 Update: GitPython-3.1.32-1.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 38 Update: GitPython-3.1.32-1.fc38 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: GitPython-3.1.30-1.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: GitPython-3.1.30-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: GitPython-3.1.30-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: GitPython-3.1.30-1.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Remote Code Execution (RCE) in gitpython | CVE-2022-24439 | Snyk |
CONFIRM |
security.snyk.io |
|
| N/A |
CONFIRM |
github.com |
|
| [SECURITY] Fedora 37 Update: GitPython-3.1.32-1.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| GitPython/base.py at bec61576ae75803bc4e60d8de7a629c194313d1c · gitpython-developers/GitPython · GitHub |
MITRE |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Sam Wheating
Legacy QID Mappings
- 184908 Debian Security Update for python-git (CVE-2022-24439)
- 199509 Ubuntu Security Notification for GitPython Vulnerability (USN-5968-1)
- 242363 Red Hat Update for Satellite 6.13.5 (RHSA-2023:5931)
- 283577 Fedora Security Update for GitPython (FEDORA-2022-8146a727a8)
- 283582 Fedora Security Update for GitPython (FEDORA-2022-ce7369b9ec)
- 284433 Fedora Security Update for GitPython (FEDORA-2023-1ec4e542f9)
- 6000125 Debian Security Update for python-git (DLA 3502-1)
- 710784 Gentoo Linux GitPython Code Execution via Crafted Input Vulnerability (GLSA 202311-01)