Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.
This is fixed in 3.1.59, and GitPython is at a later version in all Fedora and EPEL branches, except for EPEL8, which cannot be updated. It’s a real waste of time having to close bugs like this. Comparing the version number in the advisory with the version number in the repos is the lowest-hanging of all possible fruit, so it’s frustrating that it still hasn’t been attempted.