[GHSA-cwvm-v4w8-q58c] Blind local file inclusion #2753
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Updates
Comments
The fix in GitPython 3.1.35 was incomplete, as discussed in gitpython-developers/GitPython#1672. A new release, https://github.com/gitpython-developers/GitPython/releases/tag/3.1.37, includes a proper fix. The maintainer has updated the advisory associated with the repository, GHSA-cwvm-v4w8-q58c, to indicate that the fully patched version is 3.1.37 instead of any earlier version.
This change proposes the corresponding change in the GitHub Advisory Database, which would make both advisories convey the same, up-to-date information. The maintainer of GitPython, @Byron, has requested that this be done (gitpython-developers/GitPython#1672 (comment), gitpython-developers/GitPython#1672 (comment)).
This is based on a preference, in this case, to update the existing advisory and not to create a new one (as noted in the linked comments above). However, if this change to the advisory would not be sufficient to raise Dependabot alerts, that may be relevant.