THREAT OPS › Threat News › [GHSA] GHSA-hmq2-w58f-27jc (high) — GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
[GHSA] GHSA-hmq2-w58f-27jc (high) — GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
GHSA-hmq2-w58f-27jc Severity: high CVE: None
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
### Summary GitPython computes the on-disk location of a submodule's separate Git directory (`.git/modules/<name>`) from the submodule's `.gitmodules` section name with no validation. Because that name is fully attacker-control
MITRE ATT&CK techniques
- Written ContentT1683.001
Indicators of compromise
- CVE-2018-11235cve
Original source: https://github.com/advisories/GHSA-hmq2-w58f-27jc