Bug 2231474 (TRIAGE-CVE-2023-40267) - TRIAGE-CVE-2023-40267 GitPython: Insecure non-multi options in clone and clone_from is not blocked
Summary: TRIAGE-CVE-2023-40267 GitPython: Insecure non-multi options in clone and clon...
Keywords:
Status: NEW
Alias: TRIAGE-CVE-2023-40267
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2231475 2231476 2231477 2231483 2231485 2231486 2231487 2231488 2231481 2231482 2231484
Blocks: 2231478
TreeView+ depends on / blocked
 
Reported: 2023-08-11 17:03 UTC by Pedro Sampaio
Modified: 2023-08-15 19:02 UTC (History)
47 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Pedro Sampaio 2023-08-11 17:03:49 UTC
GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

References:

https://github.com/gitpython-developers/GitPython/commit/ca965ecc81853bca7675261729143f54e5bf4cdd
https://github.com/gitpython-developers/GitPython/pull/1609

Comment 1 Pedro Sampaio 2023-08-11 17:04:18 UTC
Created GitPython tracking bugs for this issue:

Affects: epel-all [bug 2231476]
Affects: fedora-all [bug 2231475]
Affects: openstack-rdo [bug 2231477]


Note You need to log in before you can comment on or make changes to this bug.