Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

CVE-2023-41040: Blind local file inclusion #1638

Closed
@EliahKagan

Description

@EliahKagan

This issue is for tracking the public vulnerabilityCVE-2023-41040:

In order to resolve some git references, GitPython reads files from the.git directory, in some places the name of the file being read is provided by the user, GitPython doesn't check if this file is located outside the.git directory. This allows an attacker to make GitPython read any file from the system.

Further details, including example code, are inCVE-2023-41040.

(I'm opening this issue based on the idea in#1635 (comment) that it's useful to have issues for these. This CVE has been mentioned in#1635, but if#1636 is merged then#1635 may be closed.#1636 fixesCVE-2023-40590 but doesnot also fixCVE-2023-41040.)

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions


      [8]ページ先頭

      ©2009-2025 Movatter.jp