Repository navigation
CVE-2022-24439: <gitpython::clone> 'ext::sh -c touch% /tmp/pwned' for remote code execution #1515
Description
Activity
I am aware, have been informed and we can track it here. Thanks a lot for setting up this issue so timely.
- changed the title
[-]CVE-2022-24439[/-][+]CVE-2022-24439: `<gitpython::clone> 'ext::sh -c touch% /tmp/pwned'` for remote code execution[/+]on Dec 6, 2022 @Byron, had Snyk or Sam Wheating (@SamWheating?) contacted you previously about this or did you learn about it independently? I'm curious given there's no reference to any upstream report in the above Snyk report.
Reacted by Santos GallegosI reached out to Snyk, who I believe got in touch with the maintainers.
I reached out to Snyk, who I believe got in touch with the maintainers.
What makes you think that? Again, just curious given there doesn't seem to be any indication of that happening according to their report. Also, why did you go to Snyk rather than to upstream?
Snyk did reach out to me by email, to my mind all this went pretty well. By publishing the issue the community can contribute a mitigation.
Yeah, seems fine to me. It would have been nice to have an existing public report to go with the public release of the CVE so that all the people who handle CVEs (myself, and the reporter of this issue, for example) would know that the issue is already known to upstream and we don't have to spend time extracting that information via issues like this.
Thank you for the insight.
Looks like this same vulnerability has been reported in another git library (simple-git), https://www.cve.org/CVERecord?id=CVE-2022-25912.
They added an option to opt-in in to the insecure behavior
- https://github.com/steveukx/git-js/blob/main/docs/PLUGIN-UNSAFE-ACTIONS.md#overriding-allowed-protocols
- https://github.com/steveukx/git-js/blob/de570acd052660bad0165347de5d2f86a494ae1b/simple-git/src/lib/plugins/block-unsafe-operations-plugin.ts
And this should probably check for https://www.cve.org/CVERecord?id=CVE-2022-24433 too (
git clone file:///tmp/zero123 /tmp/example-new-repo --upload-pack='touch /tmp/pwn')Reacted by Sebastian ThielWhat makes you think that? Again, just curious given there doesn't seem to be any indication of that happening according to their report. Also, why did you go to Snyk rather than to upstream?
Snyk's vulnerability program is fantastic - you can report an issue to them and they will review it, triage it, try to get in contact with the maintainers and then register the CVE if applicable. It eliminates a lot of the overhead on my end and helps to ensure that a vulnerability is handled appropriately.
I didn't have a direct line to the maintainers and I didn't want to open a public issue explaining a potentially sensitive vulnerability. In this case it sounds like Snyk was able to get in touch on my behalf and handle this disclosure responsibly.
Reacted by Justin Kiggins, PhD, Mohamed El Mouctar HAIDARA, Idan and AbnomariltyInR34l17yJust thought I would ping to keep this issue active. This is a critical issue in my org. Can we get a status update? Is a fix expected soon?
No fix is plannedI don't plan to work on this directly, and this issue is triaged as 'help wanted'. Indirectly I am working on it by answering here and following up on the PR which might alleviate the problem.Reacted by Charles Perrot-Minot, Tyler Vick, Emily Coffin, Joran R. Angevaare, Ülgen Sarıkavak and Kamyar MohajeraniReacted by Sebastian Thiel- added a commit that references this issue
on Dec 13, 2022 21 remaining items
A new release was created to incorporate many security related fixes.
A special thanks goes to @stsewd who was a driving force behind implementing the fixes, and to the fine folks who discovered it.
I hope this makes the upcoming year 2023 a little more secure for everyone 🎉.
Reacted by Matt Morris, Steffen Schulz and Kevin BowenReacted by Santos Gallegos and Manuel KaufmannA new release was created to incorporate many security related fixes.
A special thanks goes to @stsewd who was a driving force behind implementing the fixes, and to the fine folks who discovered it.
I hope this makes the upcoming year 2023 a little more secure for everyone tada.
Can a release be made in Github? I imagine a nonzero number of people are watching for releases in this repository who aren't subscribed to this issue to be aware of the security impact of this release.
Reacted by Aaron Bach and offaThanks for the hint. That should be done now.
- added 2 commits that reference this issue
on Jan 10, 2023 - added a commit that references this issue
on Jan 20, 2023 - added 5 commits that reference this issue
on Nov 16, 2023 - added a commit that references this issue
on Nov 24, 2023 - added a commit that references this issue
on May 14, 2026
This appeared in the CVE feed today: https://security.snyk.io/vuln/SNYK-PYTHON-GITPYTHON-3113858
Not sure if this was reported to you before or not, reporting it here just in case.