First published: Tue Jan 16 2024(Updated: )
GitPython is a python library used to interact with Git repositories.<br>Security Fix(es):<br><li> Blind local file inclusion (CVE-2023-41040)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenStack Platform 13 | ||
GitPython |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2024:0215 is classified as moderate.
To fix RHSA-2024:0215, you should update GitPython to the latest version that addresses the blind local file inclusion vulnerability.
The impact of RHSA-2024:0215 includes the potential for unauthorized access to local files through a vulnerability in GitPython.
All versions of GitPython prior to the fixed release are affected by RHSA-2024:0215.
Yes, the Red Hat OpenStack Platform is also affected by RHSA-2024:0215.