
Cloud Vulnerability DB
A community-led vulnerabilities database
GitPython before version 3.1.32 contains a security vulnerability (CVE-2023-40267) that fails to block insecure non-multi options in clone and clone_from functions. This vulnerability exists as a result of an incomplete fix for a previous security issue (CVE-2022-24439) (NVD).
The vulnerability has been assigned a CVSS v3.1 Base Score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The issue specifically relates to the handling of non-multi options in the clone and clone_from methods, where certain insecure options were not being properly blocked (NVD).
The vulnerability could potentially allow attackers to execute arbitrary commands through maliciously crafted remote URLs or repository clone operations. Given the CVSS score of 9.8, this represents a critical security risk with potential for high impact on confidentiality, integrity, and availability (NVD).
The vulnerability has been fixed in GitPython version 3.1.32. Users are strongly advised to upgrade to this version or later. The fix includes additional validation to block insecure non-multi options in clone and clone_from operations (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."