diff options
author | Narpat Mali <narpat.mali@windriver.com> | 2023-01-12 14:58:37 +0000 |
---|---|---|
committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2023-01-26 23:37:05 +0000 |
commit | 07213601fd865e698b4f7f6bd61d824e9d8181d2 (patch) | |
tree | 1babdcb8db163079a69026de690320cb36937568 /scripts/lib/devtool/runqemu.py | |
parent | fd36d262b86192bbc547f9a1e7aada5e94dccb8d (diff) | |
download | poky-07213601fd865e698b4f7f6bd61d824e9d8181d2.tar.gz |
python3-git: fix for CVE-2022-24439
All versions of package gitpython are vulnerable to Remote Code Execution
(RCE) due to improper user input validation, which makes it possible to
inject a maliciously crafted remote URL into the clone command. Exploiting
this vulnerability is possible because the library makes external calls to
git without sufficient sanitization of input arguments.
CVE: CVE-2022-24439
Upstream-Status: Backport
Reference:
https://github.com/gitpython-developers/GitPython/discussions/1529
https://github.com/gitpython-developers/GitPython/pull/1518
https://github.com/gitpython-developers/GitPython/pull/1521
(From OE-Core rev: 55f93e3786290dfa5ac72b5969bb2793f6a98bde)
Signed-off-by: Narpat Mali <narpat.mali@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'scripts/lib/devtool/runqemu.py')
0 files changed, 0 insertions, 0 deletions