漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
GitPython before 3.1.54 Arbitrary File Overwrite via diff
Vulnerability Description
GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Vulnerability Type
参数注入或修改
Vulnerability Title
gitpython-developers GitPython 命令注入漏洞
Vulnerability Description
gitpython-developers GitPython是gitpython-developers组织的一个封装版本控制功能的Python库。 gitpython-developers GitPython 3.1.54之前版本存在命令注入漏洞,该漏洞源于Diffable.diff方法未验证通过kwargs传递的git选项,可能导致攻击者利用--output参数将补丁内容写入任意文件路径,造成任意文件覆盖。
CVSS Information
N/A
Vulnerability Type
N/A