GitPython Project GitPython 3.1.36 for Python

CPE Details

GitPython Project GitPython 3.1.36 for Python
3.1.36
2024-01-18
15h30 +00:00
2024-01-18
15h30 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:gitpython_project:gitpython:3.1.36:*:*:*:*:python:*:*

Informations

Vendor

gitpython_project

Product

gitpython

Version

3.1.36

Target Software

python

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-22190 2024-01-11 01h23 +00:00 GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run `git`, as well as when it runs `bash.exe` to interpret hooks. If either of those features are used on Windows, a malicious `git.exe` or `bash.exe` may be run from an untrusted repository. This issue has been patched in version 3.1.41.
7.8
High