VDB

CVE-2022-24439

CVE-2022-24439 PUBLISHED CVSS 8.1 HIGH

Reported by snyk · Published December 12, 2022

All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments.

Risk Scores

CVSS 3.1
8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
n/aGitPython0
PyPIGitPython0
n/aGitPython0, 0

Timeline

  • Dec 6, 2022 CVE Published
  • Dec 6, 2022 EPSS Score
  • Jan 17, 2023 EPSS Score
  • Feb 28, 2023 EPSS Score
  • Apr 12, 2023 EPSS Score
  • Jul 5, 2023 EPSS Score
  • Aug 16, 2023 EPSS Score
  • Nov 9, 2023 EPSS Score
  • Feb 1, 2024 EPSS Score
  • Mar 14, 2024 EPSS Score
  • Jun 7, 2024 EPSS Score
  • Aug 30, 2024 EPSS Score

References

…and 5 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›