在 GitPython 3.1.62 版本之前,当更新子模块时,程序未对从不信任的 文件中读取的 字段进行验证。此前的一项修复(GHSA-hmq2-w58f-27jc)引入了 以限制 字段,并且 GitPython 自身在 和 方法中应用了名为 的边界检查机制。然而,在 方法中,程序直接从原始的 值派生出绝对检出位置,而未应用该边界检查。因此,包含目录遍历组件(例如 )的 条目可能导致通过 在仓库工作树之外创建目录,并从克隆路径中的子模块 URL 填充这些目录;若使用 选项,还会通过 将其删除。 利用此漏洞需要应用
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| gitpython-developers | GitPython | < 3.1.62 |
affected |
3.1.62 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| gitpython-developers | GitPython | 0 ~ 3.1.62 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet