Title: Fix command injection by stsewd · Pull Request #1518 · gitpython-developers/GitPython · GitHub
Open Graph Title: Fix command injection by stsewd · Pull Request #1518 · gitpython-developers/GitPython
X Title: Fix command injection by stsewd · Pull Request #1518 · gitpython-developers/GitPython
Description: Add -- in some commands that receive user input and if interpreted as options could lead to remote code execution (RCE). There may be more commands that could benefit from -- so the input is never interpreted as an option, but most of those aren't dangerous. Fixed commands: push pull fetch clone/clone_from and friends archive (not sure if this one can be exploited, but it doesn't hurt adding -- :)) For anyone using GitPython and exposing any of the GitPython methods to users, make sure to always validate the input (like if starts with --). And for anyone allowing users to pass arbitrary options, be aware that some options may lead to RCE, like --exc, --upload-pack, --receive-pack, --config (#1516). Ref #1517
Open Graph Description: Add -- in some commands that receive user input and if interpreted as options could lead to remote code execution (RCE). There may be more commands that could benefit from -- so the input is never ...
X Description: Add -- in some commands that receive user input and if interpreted as options could lead to remote code execution (RCE). There may be more commands that could benefit from -- so the input is never ...
Opengraph URL: https://github.com/gitpython-developers/GitPython/pull/1518
X: @github
Domain: github.com
| route-pattern | /:user_id/:repository/pull/:id/files(.:format) |
| route-controller | pull_requests |
| route-action | files |
| fetch-nonce | v2:cfa861b0-d872-1222-b86e-1ed963279159 |
| current-catalog-service-hash | ae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b |
| request-id | EBD0:1AFE8C:178C7D7:217DB1F:69690807 |
| html-safe-nonce | 7fa4a017b197f33a7fd7f36ac57b29b2e7121430dc299d418cb288e608427c51 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJFQkQwOjFBRkU4QzoxNzhDN0Q3OjIxN0RCMUY6Njk2OTA4MDciLCJ2aXNpdG9yX2lkIjoiNjEyMjU0Mzk2MTc0MzA5OTkxMSIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | 19c44235a9261aea6bb0c9907d8cba03ea65608a5e4704ad97baaa0bff8e973c |
| hovercard-subject-tag | pull_request:1173111973 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/gitpython-developers/GitPython/pull/1518/files |
| twitter:image | https://avatars.githubusercontent.com/u/4975310?s=400&v=4 |
| twitter:card | summary_large_image |
| og:image | https://avatars.githubusercontent.com/u/4975310?s=400&v=4 |
| og:image:alt | Add -- in some commands that receive user input and if interpreted as options could lead to remote code execution (RCE). There may be more commands that could benefit from -- so the input is never ... |
| og:site_name | GitHub |
| og:type | object |
| hostname | github.com |
| expected-hostname | github.com |
| None | e6156bd4ef9f2dc8dadf4c49a8f7ed8532186388cef72eda3ccb9f0ab3b8cfca |
| turbo-cache-control | no-preview |
| diff-view | unified |
| go-import | github.com/gitpython-developers/GitPython git https://github.com/gitpython-developers/GitPython.git |
| octolytics-dimension-user_id | 503709 |
| octolytics-dimension-user_login | gitpython-developers |
| octolytics-dimension-repository_id | 1126087 |
| octolytics-dimension-repository_nwo | gitpython-developers/GitPython |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 1126087 |
| octolytics-dimension-repository_network_root_nwo | gitpython-developers/GitPython |
| turbo-body-classes | logged-out env-production page-responsive full-width |
| disable-turbo | true |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | ee2210c3e58153aae53400c942f8a7b4bbb43ec4 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width