Untrusted search path in GitPython - CVE-2023-40590
Published: September 5, 2023
Vulnerability identifier: #VU80473
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-40590
CWE-ID: CWE-426
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to usage of an untrusted search. A local user can place a malicious git.exe file into a repository directory, which will be executed during import.
The vulnerability affects Windows installations only.
Affected software
GitPython
IBM Cloud Pak for Multicloud Management
IBM Cloud Pak for Multicloud Management
How to mitigate CVE-2023-40590
Install updates from vendor's website.
GitPython - update to 3.1.33
IBM Cloud Pak for Multicloud Management - update to 2.3.8
IBM Cloud Pak for Multicloud Management - update to 2.3.8