CVE-2024-22190 is an incomplete fix for a previous vulnerability in GitPython, a Python library for Git repository interaction. On Windows, GitPython can be tricked into executing a malicious git.exe or bash.exe from an untrusted repository if it uses a shell to run Git or interprets hooks. This vulnerability affects the gitpython_project gitpython product and has been patched in version 3.1.41. The vulnerability has a CVSS score of 7.8 (HIGH), indicating a significant risk. It requires user interaction (UI:R) and local access (AV:L), but once exploited, it can lead to high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). The attack complexity is low (AC:L). Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for a large percentage of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.41CPE matchmatch criteria | cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.