CVE Vulnerabilities

CVE-2023-40267

Published: Aug 11, 2023 | Modified: Nov 03, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
9.8 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

Affected Software

NameVendorStart VersionEnd Version
GitpythonGitpython_project*3.1.32 (excluding)
Red Hat Ansible Automation Platform 2.3 for RHEL 8RedHatautomation-controller-0:4.3.13-1.el8ap*
Red Hat Ansible Automation Platform 2.3 for RHEL 9RedHatautomation-controller-0:4.3.13-1.el9ap*
Red Hat Ansible Automation Platform 2.4 for RHEL 8RedHatautomation-controller-0:4.4.3-1.el8ap*
Red Hat Ansible Automation Platform 2.4 for RHEL 8RedHatpython3x-gitpython-0:3.1.32-1.el8ap*
Red Hat Ansible Automation Platform 2.4 for RHEL 9RedHatautomation-controller-0:4.4.3-1.el9ap*
Red Hat Ansible Automation Platform 2.4 for RHEL 9RedHatpython-gitpython-0:3.1.32-1.el9ap*
Red Hat Satellite 6.13 for RHEL 8RedHatpython-gitpython-0:3.1.32-1.el8pc*
Red Hat Satellite 6.13 for RHEL 8RedHatpython-gitpython-0:3.1.32-1.el8pc*
Red Hat Satellite 6.14 for RHEL 8RedHatpython-gitpython-0:3.1.32-1.el8pc*
Red Hat Satellite 6.14 for RHEL 8RedHatpython-gitpython-0:3.1.32-1.el8pc*
Python-gitUbuntubionic*
Python-gitUbuntuesm-apps/bionic*
Python-gitUbuntuesm-apps/focal*
Python-gitUbuntuesm-apps/jammy*
Python-gitUbuntuesm-apps/xenial*
Python-gitUbuntuesm-infra-legacy/trusty*
Python-gitUbuntufocal*
Python-gitUbuntujammy*
Python-gitUbuntulunar*
Python-gitUbuntumantic*
Python-gitUbuntuoracular*
Python-gitUbuntuplucky*
Python-gitUbuntutrusty*
Python-gitUbuntutrusty/esm*
Python-gitUbuntuxenial*

References