Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Mageia 8 MGASA-2023-0001 Critical: Python-Gitpython Remote Code Execution

mageia
Calendar Grey January 13, 2023
Dist Mageia Esm H88
MGASA-2023-0002 addresses RCE vulnerability in python-django on 20 Feb 2023 through enhanced URL parsing.
Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command

Summary

Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments. This is only relevant when enabling the ext transport protocol (CVE-2022-24439)

References

- https://bugs.mageia.org/show_bug.cgi?id=31242

- https://security.snyk.io/vuln/SNYK-PYTHON-GITPYTHON-3113858

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/IKMVYKLWX62UEYKAN64RUZMOIAMZM5JN/

- https://www.cve.org/CVERecord?id=CVE-2022-24439

Resolution

SRPMS

- 8/core/python-gitpython-3.1.30-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 13 Jan 2023
URL: https://advisories.mageia.org/MGASA-2023-0001.html
Type: security
CVE: CVE-2022-24439

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here