CVE-2022-24439
All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments.
- Gitpython Project Gitpython
- < 3.1.30
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 5.4% (92th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2022-12-12
CVE-2022-24439 at NVD
1 known exploit for CVE-2022-24439
Proof-of-concept code and exploit modules indexed by Sploitus