CVE-2026-67322
Red Hat Security Advisory: satellite/iop-vulnerability-engine-rhel9 container image available as a Technology Preview
Beschreibung
GitPython vor Version 3.1.52 ist anfällig für die Exfiltration von Umgebungsvariablen in `Repo.clone_from()`. Die vom Aufrufer bereitgestellte Remote-URL wird durch `Git.polish_url()` weitergeleitet, das auf Nicht-Cygwin-Plattformen `os.path.expandvars()` auf die URL anwendet, bevor es `git clone` aufruft. Ein Angreifer, der den Clone-URL kontrolliert, kann `$NAME` oder `${NAME}`-Tokens einbetten, die zu den Werten der Umgebungsvariablen des Hostprozesses erweitert werden (z.B. `AWS_SECRET_ACCESS_KEY` oder `GITHUB_TOKEN`). Die resultierende URL enthält nun das Geheimnis und wird während des Clone-Versuchs über das Netzwerk an einen von einem Angreifer kontrollierten Host übertragen, wodurch das Geheimnis offengelegt wird.
Metriken
Weakness-Klassen (CWE)
CWE-200Class
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Modified2026-08-03 19:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Reference: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573
- SSVC: {"id":"CVE-2026-67322","role":"CISA Coordinator","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalI…
Betroffene Betriebssysteme
linux
redhat / enterprise_linux_ai3.0
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
encode
starlette0.8.3 – 1.0.1
gitpython_project
gitpython3.1.51
gitpython_project
gitpython3.1.52
pypi
aiohttp0.1
pypi
aiohttp0.10.0
pypi
aiohttp0.10.1
pypi
aiohttp0.10.2
pypi
aiohttp0.11.0
pypi
aiohttp0.12.0
pypi
aiohttp0.13.0
pypi
aiohttp0.13.1
pypi
aiohttp0.14.0
pypi
aiohttp0.14.1
pypi
aiohttp0.14.2
pypi
aiohttp0.14.3
pypi
aiohttp0.14.4
pypi
aiohttp0.15.0
pypi
aiohttp0.15.1
pypi
aiohttp0.15.2
pypi
aiohttp0.15.3
pypi
aiohttp0.16.0
pypi
aiohttp0.16.1
pypi
aiohttp0.16.2
pypi
aiohttp0.16.3
Quellen & Referenzen
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mfx4-hv73-q22vweb
- https://github.com/aio-libs/aiohttp/pull/13017web
- https://github.com/aio-libs/aiohttp/commit/6ae358f0983c3f4d6f67692b2f8e65dc8e091c98web
- https://github.com/aio-libs/aiohttppackage
- https://github.com/aio-libs/aiohttp/releases/tag/v3.14.2web
- https://pypi.org/project/aiohttppackage
- https://github.com/advisories/GHSA-mfx4-hv73-q22vadvisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-69243advisory
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-956x-8gvw-wg5vweb
- https://github.com/gitpython-developers/GitPython/pull/2163web
- https://github.com/gitpython-developers/GitPython/commit/701ce32fe5ba8cb622c0e0342a376a6beb47d738web
- https://github.com/gitpython-developers/GitPythonpackage
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51web
- https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-unguarded-git-optionsthird-party-advisory
- https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mrweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-48710advisory
- https://github.com/Kludex/starlette/commit/764dab0dcfb9033d75442d7a359645c9f94648c6web
- https://www.x41-dsec.de/lab/advisories/x41-2026-002-starletteweb
- https://www.secwest.net/starletteweb
- https://www.cve.org/CVERecord?id=CVE-2026-48710web
Verknüpfte CVEs
- CVE-2026-69244
AIOHTTP ist ein asynchroner HTTP-Client/Server-Framework für asyncio und Python.
high - CVE-2026-69243
AIOHTTP ist ein asynchroner HTTP-Client/Server-Framework für asyncio und Python.
medium - CVE-2026-67325
GitPython vor Version 3.1.51 enthält eine unvollständige Blacklist für die Befehlseinschleusung, die das Abkürzungsfeature von gits Lango…
highCVSSv3 8.8 - CVE-2026-67323
GitPython vor Version 3.1.51 schützt sich nicht ausreichend gegen gefährliche Git-Optionen, die als Schlüsselwortargumente in `Repo.archi…
highCVSSv3 8.4 - CVE-2026-48710Aktiv ausgenutzt
Starlette ist ein leichtgewichtiges ASGI-Framework/Toolkit.
criticalCVSSv3 6.5