GHSA-mq5p-2mcr-m52j
Dashboard / Vulnerabilities / GHSA-mq5p-2mcr-m52j
GHSA-mq5p-2mcr-m52j
Summary: Code injection in nbgitpuller
Details: ### Impact Due to an unsanitized input, visiting maliciously crafted links could result in arbitrary code execution in the user environment. ### Patches 0.10.2 ### Workarounds None, other than upgrade to 0.10.2 or downgrade to 0.8.x. ### For more information If you have any questions or comments about this advisory: * Open an issue in [nbgitpuller](https://github.com/jupyterhub/nbgitpuller/issues) * Email our security team at [[email protected]](mailto:[email protected])
References: https://github.com/jupyterhub/nbgitpuller/security/advisories/GHSA-mq5p-2mcr-m52j, https://nvd.nist.gov/vuln/detail/CVE-2021-39160, https://github.com/jupyterhub/nbgitpuller/commit/07690644f29a566011dd0d7ba14cae3eb0490481, https://github.com/jupyterhub/nbgitpuller, https://github.com/jupyterhub/nbgitpuller/blob/main/CHANGELOG.md#0102---2021-08-25, https://github.com/pypa/advisory-database/tree/main/vulns/nbgitpuller/PYSEC-2021-315.yaml
Affected packages
Package
Name: nbgitpuller
Purl: pkg:pypi/nbgitpuller
Affected ranges
Type: ECOSYSTEM
Events:
