Untrusted search path in GitPython - CVE-2024-22190

 

Untrusted search path in GitPython - CVE-2024-22190

Published: January 15, 2024


Vulnerability identifier: #VU85371
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22190
CWE-ID: CWE-426
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to incomplete fix for #VU80473 (CVE-2023-40590). A local user can place a malicious binary (e.g. git.exe or bash.exe) into a specific location on the system and execute arbitrary code with escalated privileges.


Affected software

GitPython
QRadar Suite
IBM Process Mining
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data

How to mitigate CVE-2024-22190

Install updates from vendor's website.

GitPython - update to 3.1.41
QRadar Suite - update to 1.10.18.0
IBM Process Mining - update to 1.14.4
IBM Cloud Pak for Watson AIOps - update to 4.6.0
DB2 on Cloud Pak for Data - update to 4.8.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5

External References

Related Security Bulletins