3.1.58
16 years ago
1 days ago
Known vulnerabilities in the gitpython package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
GitPython is a python library used to interact with Git repositories Affected versions of this package are vulnerable to External Control of File Name or Path in the How to fix External Control of File Name or Path? Upgrade | [,3.1.57) |
GitPython is a python library used to interact with Git repositories Affected versions of this package are vulnerable to External Control of File Name or Path in the How to fix External Control of File Name or Path? Upgrade | [,3.1.57) |
GitPython is a python library used to interact with Git repositories Affected versions of this package are vulnerable to External Control of File Name or Path via the forwarding of unguarded options in the How to fix External Control of File Name or Path? Upgrade | [,3.1.57) |
GitPython is a python library used to interact with Git repositories Affected versions of this package are vulnerable to Arbitrary Argument Injection via the How to fix Arbitrary Argument Injection? Upgrade | [,3.1.56) |
GitPython is a python library used to interact with Git repositories Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') through improper sanitization of section or subsection names in configuration headers. An attacker can inject arbitrary configuration directives by supplying specially crafted submodule names, leading to the execution of malicious commands during subsequent git operations. How to fix Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')? Upgrade | [,3.1.53) |
GitPython is a python library used to interact with Git repositories Affected versions of this package are vulnerable to Information Exposure in the How to fix Information Exposure? Upgrade | [,3.1.55) |
GitPython is a python library used to interact with Git repositories Affected versions of this package are vulnerable to Arbitrary Argument Injection via the How to fix Arbitrary Argument Injection? Upgrade | [,3.1.54) |
GitPython is a python library used to interact with Git repositories Affected versions of this package are vulnerable to Incomplete List of Disallowed Inputs via the How to fix Incomplete List of Disallowed Inputs? Upgrade | [,3.1.54) |
GitPython is a python library used to interact with Git repositories Affected versions of this package are vulnerable to Arbitrary Argument Injection via the How to fix Arbitrary Argument Injection? Upgrade | [,3.1.54) |