Gitpython Project

Gitpython

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 11.01.2024 02:15:48
  • Zuletzt bearbeitet 21.11.2024 08:55:45

GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run `git`, as well as when it runs `bash.exe` to interpret ...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 30.08.2023 22:15:09
  • Zuletzt bearbeitet 03.11.2025 22:16:26

GitPython is a python library used to interact with Git repositories. In order to resolve some git references, GitPython reads files from the `.git` directory, in some places the name of the file being read is provided by the user, GitPython doesn't ...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 28.08.2023 18:15:08
  • Zuletzt bearbeitet 21.11.2024 08:19:46

GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for the current working directory, and after that the PATH environment. GitPython defaults to use the `git` command, if a user runs G...

  • EPSS 0.35%
  • Veröffentlicht 11.08.2023 07:15:09
  • Zuletzt bearbeitet 03.11.2025 22:16:26

GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

Exploit
  • EPSS 66.39%
  • Veröffentlicht 06.12.2022 05:15:11
  • Zuletzt bearbeitet 03.11.2025 22:15:57

All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possibl...