漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
GitPython before 3.1.54 Remote Code Execution via --template
Vulnerability Description
GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout hooks that execute when git clones the repository.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
gitpython-developers GitPython 命令注入漏洞
Vulnerability Description
gitpython-developers GitPython是gitpython-developers组织的一个封装版本控制功能的Python库。 GitPython 3.1.54之前版本存在命令注入漏洞,该漏洞源于unsafe_git_clone_options中的不完整拒绝列表省略了--template,可能导致攻击者在克隆操作期间通过恶意post-checkout钩子执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A