VYPR

rpm package

opensuse/python-GitPython&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/python-GitPython&distro=openSUSE%20Tumbleweed

Vulnerabilities (23)

  • CVE-2023-40590HigAug 28, 2023
    affected < 3.1.56-1.1fixed 3.1.56-1.1

    GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for the current working directory, and after that the PATH environment. GitPython defaults to use the `git` command, if a user runs GitPython from a repo has a `gi

  • CVE-2023-40267CriAug 11, 2023
    affected < 3.1.56-1.1fixed 3.1.56-1.1

    GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

  • CVE-2022-24439HigDec 6, 2022
    affected < 3.1.44-1.1fixed 3.1.44-1.1

    All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes ex

Page 2 of 2