Skip to content
This repository has been archived by the owner on Feb 7, 2024. It is now read-only.

CVE-2023-40267 (Critical) detected in GitPython-3.1.29-py3-none-any.whl #1316

Closed
mend-for-github-com bot opened this issue Aug 11, 2023 · 1 comment
Closed
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource needs-attention

Comments

@mend-for-github-com
Copy link
Contributor

mend-for-github-com bot commented Aug 11, 2023

CVE-2023-40267 - Critical Severity Vulnerability

Vulnerable Library - GitPython-3.1.29-py3-none-any.whl

GitPython is a python library used to interact with Git repositories

Library home page: https://files.pythonhosted.org/packages/1f/d3/020efb312a7d25fa00e144497a33378d415552e5581be080a99017af6d39/GitPython-3.1.29-py3-none-any.whl

Path to dependency file: /scripts/automation/automerge/requirements.txt

Path to vulnerable library: /scripts/automation/automerge/requirements.txt

Dependency Hierarchy:

  • GitPython-3.1.29-py3-none-any.whl (Vulnerable Library)

Found in base branch: main

Vulnerability Details

GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

Publish Date: 2023-08-11

URL: CVE-2023-40267

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2023-08-11

Fix Resolution: GitPython - 3.1.32


⛑️ Automatic Remediation will be attempted for this issue.

@mend-for-github-com mend-for-github-com bot added the Mend: dependency security vulnerability Security vulnerability detected by WhiteSource label Aug 11, 2023
@mend-for-github-com mend-for-github-com bot changed the title CVE-2023-40267 (Medium) detected in GitPython-3.1.29-py3-none-any.whl CVE-2023-40267 (Critical) detected in GitPython-3.1.29-py3-none-any.whl Aug 18, 2023
@stale
Copy link

stale bot commented Sep 16, 2023

This issue/pull request has been marked as needs attention as it has been left pending without new activity for 4 days. Tagging @shailesh-vaidya for appropriate assignment. Sorry for the delay & Thank you for contributing to CORTX. We will get back to you as soon as possible.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource needs-attention
Projects
None yet
Development

No branches or pull requests

1 participant