CVE-2024-22190

CVSS V2 None CVSS V3 None
Description
GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run `git`, as well as when it runs `bash.exe` to interpret hooks. If either of those features are used on Windows, a malicious `git.exe` or `bash.exe` may be run from an untrusted repository. This issue has been patched in version 3.1.41.
Overview
  • CVE ID
  • CVE-2024-22190
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-01-11T01:23:17.944Z
  • Last Modified Date
  • 2024-01-11T01:23:17.944Z
History
Created Old Value New Value Data Type Notes
2024-06-26 09:02:34 Added to TrackCVE