Safety vulnerability ID: 60350
The information on this page was manually curated by our Cybersecurity Intelligence Team.
GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.
Latest version: 3.1.43
GitPython is a Python library used to interact with Git repositories
GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439. See CVE-2023-40267.
MISC:https://github.com/gitpython-developers/GitPython/commit/ca965ecc81853bca7675261729143f54e5bf4cdd: https://github.com/gitpython-developers/GitPython/commit/ca965ecc81853bca7675261729143f54e5bf4cdd
MISC:https://github.com/gitpython-developers/GitPython/pull/1609: https://github.com/gitpython-developers/GitPython/pull/1609
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application