PT-2022-7372 · Gitpython+5 · Gitpython+5

Sam Wheating

·

Published

2022-12-06

·

Updated

2025-03-06

·

CVE-2022-24439

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions gitpython versions (affected versions not specified)
Description The issue is related to improper user input validation in the gitpython library, which allows for Remote Code Execution (RCE) due to insufficient sanitization of input arguments when making external calls to git. This enables an attacker to inject a maliciously crafted remote URL into the clone command. The vulnerability is exploited because of the library's failure to properly clean input arguments before passing them to git.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-8415
BDU:2024-04480
CVE-2022-24439
DLA-3502-1
DLA-3939-1
GHSA-HCPJ-QP55-GFPH
MGASA-2023-0001
OESA-2023-1529
OPENSUSE-SU-2024:12596-1
OPENSUSE-SU-2024:13510-1
OPENSUSE-SU-2025:14858-1
PYSEC-2022-42992
RHSA-2023:5931
USN-5968-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Red Os
Ubuntu
Gitpython