Title: Fix command injection by stsewd · Pull Request #1518 · gitpython-developers/GitPython · GitHub
Open Graph Title: Fix command injection by stsewd · Pull Request #1518 · gitpython-developers/GitPython
X Title: Fix command injection by stsewd · Pull Request #1518 · gitpython-developers/GitPython
Description: Add -- in some commands that receive user input and if interpreted as options could lead to remote code execution (RCE). There may be more commands that could benefit from -- so the input is never interpreted as an option, but most of those aren't dangerous. Fixed commands: push pull fetch clone/clone_from and friends archive (not sure if this one can be exploited, but it doesn't hurt adding -- :)) For anyone using GitPython and exposing any of the GitPython methods to users, make sure to always validate the input (like if starts with --). And for anyone allowing users to pass arbitrary options, be aware that some options may lead to RCE, like --exc, --upload-pack, --receive-pack, --config (#1516). Ref #1517
Open Graph Description: Add -- in some commands that receive user input and if interpreted as options could lead to remote code execution (RCE). There may be more commands that could benefit from -- so the input is never ...
X Description: Add -- in some commands that receive user input and if interpreted as options could lead to remote code execution (RCE). There may be more commands that could benefit from -- so the input is never ...
Opengraph URL: https://github.com/gitpython-developers/GitPython/pull/1518
X: @github
Domain: github.com
| route-pattern | /:user_id/:repository/pull/:id/checks(.:format) |
| route-controller | pull_requests |
| route-action | checks |
| fetch-nonce | v2:30a4a22a-ef1d-984a-06ed-65659d37a9fc |
| current-catalog-service-hash | 87dc3bc62d9b466312751bfd5f889726f4f1337bdff4e8be7da7c93d6c00a25a |
| request-id | A768:22008D:840248:B8AD70:69690874 |
| html-safe-nonce | 8c9cb509da6c571dc00f9ac9a5e21319bf22340b9d48812f2251a6f61487583d |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJBNzY4OjIyMDA4RDo4NDAyNDg6QjhBRDcwOjY5NjkwODc0IiwidmlzaXRvcl9pZCI6IjUwMTU3NjA0MDQ1NzkxNTgxMzIiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ== |
| visitor-hmac | 6ecbfe7f5be630e6479de1867c0c3b4654d2eddd71e98bc7265b789a890c3c6e |
| hovercard-subject-tag | pull_request:1173111973 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,checks,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/gitpython-developers/GitPython/pull/1518/checks |
| twitter:image | https://avatars.githubusercontent.com/u/4975310?s=400&v=4 |
| twitter:card | summary_large_image |
| og:image | https://avatars.githubusercontent.com/u/4975310?s=400&v=4 |
| og:image:alt | Add -- in some commands that receive user input and if interpreted as options could lead to remote code execution (RCE). There may be more commands that could benefit from -- so the input is never ... |
| og:site_name | GitHub |
| og:type | object |
| hostname | github.com |
| expected-hostname | github.com |
| None | e6156bd4ef9f2dc8dadf4c49a8f7ed8532186388cef72eda3ccb9f0ab3b8cfca |
| turbo-cache-control | no-preview |
| go-import | github.com/gitpython-developers/GitPython git https://github.com/gitpython-developers/GitPython.git |
| octolytics-dimension-user_id | 503709 |
| octolytics-dimension-user_login | gitpython-developers |
| octolytics-dimension-repository_id | 1126087 |
| octolytics-dimension-repository_nwo | gitpython-developers/GitPython |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 1126087 |
| octolytics-dimension-repository_network_root_nwo | gitpython-developers/GitPython |
| turbo-body-classes | logged-out env-production page-responsive full-width full-width-p-0 |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | ee2210c3e58153aae53400c942f8a7b4bbb43ec4 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width