CVE-2023-40267

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/08/2023
Last modified:
07/11/2023

Description

GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:* 3.1.32 (excluding)