vulnerability

Ubuntu: USN-6326-1 (CVE-2023-40267): GitPython vulnerability

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Aug 11, 2023
Added
Sep 5, 2023
Modified
Jan 28, 2025

Description

GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

Solutions

ubuntu-pro-upgrade-python-gitubuntu-pro-upgrade-python3-git
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.