CVE-2024-22190
Untrusted search path under some conditions on Windows allows arbitrary code execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run `git`, as well as when it runs `bash.exe` to interpret hooks. If either of those features are used on Windows, a malicious `git.exe` or `bash.exe` may be run from an untrusted repository. This issue has been patched in version 3.1.41.
GitPython es una librería de Python que se utiliza para interactuar con los repositorios de Git. Existe una solución incompleta para CVE-2023-40590. En Windows, GitPython usa una ruta de búsqueda que no es de confianza si usa un shell para ejecutar `git`, así como cuando ejecuta `bash.exe` para interpretar ganchos. Si cualquiera de esas funciones se utiliza en Windows, se puede ejecutar un `git.exe` o `bash.exe` malicioso desde un repositorio que no es de confianza. Este problema se solucionó en la versión 3.1.41.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-01-08 CVE Reserved
- 2024-01-11 CVE Published
- 2024-09-03 CVE Updated
- 2025-02-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-426: Untrusted Search Path
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/gitpython-developers/GitPython/commit/ef3192cc414f2fd9978908454f6fd95243784c7f | 2024-01-18 | |
https://github.com/gitpython-developers/GitPython/pull/1792 | 2024-01-18 |
URL | Date | SRC |
---|---|---|
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-2mqj-m65w-jghx | 2024-01-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gitpython Project Search vendor "Gitpython Project" | Gitpython Search vendor "Gitpython Project" for product "Gitpython" | < 3.1.41 Search vendor "Gitpython Project" for product "Gitpython" and version " < 3.1.41" | python |
Affected
|