QID 996668

Date Published: 2024-01-15

QID 996668: Python (Pip) Security Update for GitPython (GHSA-2mqj-m65w-jghx)

This issue exists because of an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run git, as well as when it runs bash.exe to interpret hooks. If either of those features are used on Windows, a malicious git.exe or bash.exe may be run from an untrusted repository.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-2mqj-m65w-jghx for updates and patch information.
    Vendor References

    CVEs related to QID 996668

    Software Advisories
    Advisory ID Software Component Link
    GHSA-2mqj-m65w-jghx GitPython URL Logo github.com/advisories/GHSA-2mqj-m65w-jghx