Skip to content

Fix CVE-2023-40267#14388

Merged
TheRealHaoLiu merged 1 commit intoansible:develfrom
TheRealHaoLiu:fix-CVE-2023-40267
Aug 28, 2023
Merged

Fix CVE-2023-40267#14388
TheRealHaoLiu merged 1 commit intoansible:develfrom
TheRealHaoLiu:fix-CVE-2023-40267

Conversation

@TheRealHaoLiu
Copy link
Copy Markdown
Member

SUMMARY

CVE-2023-40267 GitPython: Insecure non-multi options in clone and clone_from is not blocked https://bugzilla.redhat.com/show_bug.cgi?id=2231474

GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

References:
gitpython-developers/GitPython@ca965ec gitpython-developers/GitPython#1609

ISSUE TYPE
  • Bug, Docs Fix or other nominal change
COMPONENT NAME
  • Other
AWX VERSION
awx: 22.7.1.dev19+g853205a415
ADDITIONAL INFORMATION

CVE-2023-40267 GitPython: Insecure non-multi options in clone and clone_from is not blocked
https://bugzilla.redhat.com/show_bug.cgi?id=2231474

GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

References:
gitpython-developers/GitPython@ca965ec
gitpython-developers/GitPython#1609
@github-actions github-actions Bot added the dependencies Pull requests that update a dependency file label Aug 28, 2023
@TheRealHaoLiu TheRealHaoLiu merged commit ffa5986 into ansible:devel Aug 28, 2023
@TheRealHaoLiu TheRealHaoLiu deleted the fix-CVE-2023-40267 branch August 28, 2023 19:35
kdelee pushed a commit to kdelee/awx that referenced this pull request May 8, 2024
CVE-2023-40267 GitPython: Insecure non-multi options in clone and clone_from is not blocked https://bugzilla.redhat.com/show_bug.cgi?id=2231474

GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

References:
gitpython-developers/GitPython@ca965ec gitpython-developers/GitPython#1609
djyasin pushed a commit to djyasin/awx that referenced this pull request Sep 16, 2024
CVE-2023-40267 GitPython: Insecure non-multi options in clone and clone_from is not blocked https://bugzilla.redhat.com/show_bug.cgi?id=2231474

GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

References:
gitpython-developers/GitPython@ca965ec gitpython-developers/GitPython#1609
djyasin pushed a commit to djyasin/awx that referenced this pull request Nov 11, 2024
CVE-2023-40267 GitPython: Insecure non-multi options in clone and clone_from is not blocked https://bugzilla.redhat.com/show_bug.cgi?id=2231474

GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

References:
gitpython-developers/GitPython@ca965ec gitpython-developers/GitPython#1609
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants