Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
GitPython before 3.1.51 Command Injection via unguarded Git options
Vulnerability Description
GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leading-dash revision arguments, so a revision like --output=<path> can cause Git to open and truncate an arbitrary file. Exploitation requires an application that passes attacker-controlled arguments to these methods.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Vulnerability Title
gitpython-developers GitPython 命令注入漏洞
Vulnerability Description
gitpython-developers GitPython是gitpython-developers组织的数据库系统。 gitpython-developers GitPython 3.1.51之前版本存在命令注入漏洞,该漏洞源于Repo.archive()和git.ls_remote()未防范危险的Git选项作为关键字参数,可能导致命令注入;同时Repo.iter_commits()和Repo.blame()未检查前导破折号修订参数,可导致打开并截断任意文件。
CVSS Information
N/A
Vulnerability Type
N/A