CVE Vulnerabilities

CVE-2023-40267

Published: Aug 11, 2023 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
9.8 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

Affected Software

Name Vendor Start Version End Version
Gitpython Gitpython_project * 3.1.32 (excluding)
Red Hat Ansible Automation Platform 2.3 for RHEL 8 RedHat automation-controller-0:4.3.13-1.el8ap *
Red Hat Ansible Automation Platform 2.3 for RHEL 9 RedHat automation-controller-0:4.3.13-1.el9ap *
Red Hat Ansible Automation Platform 2.4 for RHEL 8 RedHat automation-controller-0:4.4.3-1.el8ap *
Red Hat Ansible Automation Platform 2.4 for RHEL 8 RedHat python3x-gitpython-0:3.1.32-1.el8ap *
Red Hat Ansible Automation Platform 2.4 for RHEL 9 RedHat automation-controller-0:4.4.3-1.el9ap *
Red Hat Ansible Automation Platform 2.4 for RHEL 9 RedHat python-gitpython-0:3.1.32-1.el9ap *
Red Hat Satellite 6.13 for RHEL 8 RedHat python-gitpython-0:3.1.32-1.el8pc *
Red Hat Satellite 6.13 for RHEL 8 RedHat python-gitpython-0:3.1.32-1.el8pc *
Red Hat Satellite 6.14 for RHEL 8 RedHat python-gitpython-0:3.1.32-1.el8pc *
Red Hat Satellite 6.14 for RHEL 8 RedHat python-gitpython-0:3.1.32-1.el8pc *
Python-git Ubuntu bionic *
Python-git Ubuntu esm-apps/bionic *
Python-git Ubuntu esm-apps/focal *
Python-git Ubuntu esm-apps/jammy *
Python-git Ubuntu esm-apps/xenial *
Python-git Ubuntu lunar *
Python-git Ubuntu mantic *
Python-git Ubuntu trusty *
Python-git Ubuntu trusty/esm *
Python-git Ubuntu xenial *

References