Bug 2231474 (CVE-2023-40267) - CVE-2023-40267 GitPython: Insecure non-multi options in clone and clone_from is not blocked
Summary: CVE-2023-40267 GitPython: Insecure non-multi options in clone and clone_from ...
Keywords:
Status: NEW
Alias: CVE-2023-40267
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2231477 2231483 2231485 2231487 2231488 2231475 2231476 2231481 2231482 2231484 2231486 2238378
Blocks: 2231478
TreeView+ depends on / blocked
 
Reported: 2023-08-11 17:03 UTC by Pedro Sampaio
Modified: 2024-03-21 02:39 UTC (History)
49 users (show)

Fixed In Version: git-python 3.1.32
Doc Type: If docs needed, set a value
Doc Text:
An improper input validation vulnerability was found in GitPython. This flaw allows an attacker to inject a maliciously crafted remote URL into the clone command, possibly leading to remote code execution.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2023:4971 0 None None None 2023-09-05 11:50:54 UTC
Red Hat Product Errata RHSA-2023:4991 0 None None None 2023-09-06 13:03:30 UTC
Red Hat Product Errata RHSA-2023:5931 0 None None None 2023-10-19 13:13:13 UTC
Red Hat Product Errata RHSA-2023:6818 0 None None None 2023-11-08 14:17:28 UTC

Description Pedro Sampaio 2023-08-11 17:03:49 UTC
GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

References:

https://github.com/gitpython-developers/GitPython/commit/ca965ecc81853bca7675261729143f54e5bf4cdd
https://github.com/gitpython-developers/GitPython/pull/1609

Comment 1 Pedro Sampaio 2023-08-11 17:04:18 UTC
Created GitPython tracking bugs for this issue:

Affects: epel-all [bug 2231476]
Affects: fedora-all [bug 2231475]
Affects: openstack-rdo [bug 2231477]

Comment 15 errata-xmlrpc 2023-09-05 11:50:51 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.4 for RHEL 9
  Red Hat Ansible Automation Platform 2.4 for RHEL 8

Via RHSA-2023:4971 https://access.redhat.com/errata/RHSA-2023:4971

Comment 16 errata-xmlrpc 2023-09-06 13:03:27 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.3 for RHEL 9
  Red Hat Ansible Automation Platform 2.3 for RHEL 8

Via RHSA-2023:4991 https://access.redhat.com/errata/RHSA-2023:4991

Comment 18 errata-xmlrpc 2023-10-19 13:13:10 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.13 for RHEL 8

Via RHSA-2023:5931 https://access.redhat.com/errata/RHSA-2023:5931

Comment 19 errata-xmlrpc 2023-11-08 14:17:26 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.14 for RHEL 8

Via RHSA-2023:6818 https://access.redhat.com/errata/RHSA-2023:6818


Note You need to log in before you can comment on or make changes to this bug.