Visitar URL original
CVE-2022-24439: `<gitpython::clone> 'ext::sh -c touch% /tmp/pwned'` for remote code execution · Issue #1515 · gitpython-developers/GitPython · GitHub
Skip to content

CVE-2022-24439: <gitpython::clone> 'ext::sh -c touch% /tmp/pwned' for remote code execution #1515

Description

@mmuehlenhoff

This appeared in the CVE feed today: https://security.snyk.io/vuln/SNYK-PYTHON-GITPYTHON-3113858

Not sure if this was reported to you before or not, reporting it here just in case.

Activity

  1. Byron commented on Dec 6, 2022

    @Byron
    Member

    I am aware, have been informed and we can track it here. Thanks a lot for setting up this issue so timely.

  2. changed the title [-]CVE-2022-24439[/-] [+]CVE-2022-24439: `<gitpython::clone> 'ext::sh -c touch% /tmp/pwned'` for remote code execution[/+] on Dec 6, 2022
  3. ajakk commented on Dec 6, 2022

    @ajakk

    @Byron, had Snyk or Sam Wheating (@SamWheating?) contacted you previously about this or did you learn about it independently? I'm curious given there's no reference to any upstream report in the above Snyk report.

  4. SamWheating commented on Dec 6, 2022

    @SamWheating

    I reached out to Snyk, who I believe got in touch with the maintainers.

  5. ajakk commented on Dec 6, 2022

    @ajakk

    I reached out to Snyk, who I believe got in touch with the maintainers.

    What makes you think that? Again, just curious given there doesn't seem to be any indication of that happening according to their report. Also, why did you go to Snyk rather than to upstream?

  6. Byron commented on Dec 6, 2022

    @Byron
    Member

    Snyk did reach out to me by email, to my mind all this went pretty well. By publishing the issue the community can contribute a mitigation.

  7. ajakk commented on Dec 6, 2022

    @ajakk

    Yeah, seems fine to me. It would have been nice to have an existing public report to go with the public release of the CVE so that all the people who handle CVEs (myself, and the reporter of this issue, for example) would know that the issue is already known to upstream and we don't have to spend time extracting that information via issues like this.

    Thank you for the insight.

  8. stsewd commented on Dec 6, 2022

    @stsewd
    Contributor
  9. SamWheating commented on Dec 6, 2022

    @SamWheating

    What makes you think that? Again, just curious given there doesn't seem to be any indication of that happening according to their report. Also, why did you go to Snyk rather than to upstream?

    Snyk's vulnerability program is fantastic - you can report an issue to them and they will review it, triage it, try to get in contact with the maintainers and then register the CVE if applicable. It eliminates a lot of the overhead on my end and helps to ensure that a vulnerability is handled appropriately.

    https://docs.snyk.io/more-info/disclosing-vulnerabilities/disclose-a-vulnerability-in-an-open-source-package

    I didn't have a direct line to the maintainers and I didn't want to open a public issue explaining a potentially sensitive vulnerability. In this case it sounds like Snyk was able to get in touch on my behalf and handle this disclosure responsibly.

  10. jacwalte commented on Dec 8, 2022

    @jacwalte

    Just thought I would ping to keep this issue active. This is a critical issue in my org. Can we get a status update? Is a fix expected soon?

  11. Byron commented on Dec 8, 2022

    @Byron
    Member

    No fix is planned I don't plan to work on this directly, and this issue is triaged as 'help wanted'. Indirectly I am working on it by answering here and following up on the PR which might alleviate the problem.

  12. added a commit that references this issue on Dec 13, 2022
    03753c0
  13. 21 remaining items

  14. Byron commented on Dec 29, 2022

    @Byron
    Member

    A new release was created to incorporate many security related fixes.

    A special thanks goes to @stsewd who was a driving force behind implementing the fixes, and to the fine folks who discovered it.

    I hope this makes the upcoming year 2023 a little more secure for everyone 🎉.

  15. ajakk commented on Dec 30, 2022

    @ajakk

    A new release was created to incorporate many security related fixes.

    A special thanks goes to @stsewd who was a driving force behind implementing the fixes, and to the fine folks who discovered it.

    I hope this makes the upcoming year 2023 a little more secure for everyone tada.

    Can a release be made in Github? I imagine a nonzero number of people are watching for releases in this repository who aren't subscribed to this issue to be aware of the security impact of this release.

  16. Byron commented on Dec 31, 2022

    @Byron
    Member

    Thanks for the hint. That should be done now.

  17. added a commit that references this issue on May 11, 2026
  18. added a commit that references this issue on May 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions