from 0, < 0.9.9
from 0, < 0.9.9
from 0, < 0.9.10
CRITICAL9.8dulwich - security update
from 0, < 0.9.9
CRITICAL9.8Dulwich RCE Vulnerability
from 0, < 0.18.5
CRITICAL9.8Dulwich RCE Vulnerability
from 0, < 0.18.5
HIGH8.8Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows
>= 0.10.0, < 1.2.5
HIGH8.8Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows
>= 0.10.0, < 1.2.5
HIGH7.5Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped .git/hooks payload
>= 0.23.2, < 1.2.5
HIGH7.5Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped .git/hooks payload
>= 0.23.2, < 1.2.5
MEDIUM5.7Dulwich has unbounded memory allocation in receive-pack from crafted thin packs
>= 0.1.0, < 1.2.5
MEDIUM5.7Dulwich has unbounded memory allocation in receive-pack from crafted thin packs
>= 0.1.0, < 1.2.5
LOW3.3Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`
>= 0.24.0, < 1.2.5
LOW3.3Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`
>= 0.24.0, < 1.2.5
—Dulwich Vulnerable to Command Injection via Merge Driver Path
>= 0.24.0, < 1.2.5
—Dulwich Vulnerable to Command Injection via Merge Driver Path
>= 0.24.0, < 1.2.5