0001508bareos-coreGeneralpublic2023-02-07 13:59
ReporterRuth Ivimey-Cook Assigned Tobruno-at-bareos  
Status closedResolutionfixed 
Product Version22.0.0 
Summary0001508: Github reporting severe CVE on pipfile.lock
DescriptionFor many weeks now, Github Security alert digest has been reminding me that there is a security fail in pipfile.lock in my clone of the bareos repo:

Known security vulnerabilities detected
Dependency GitPython Version <= 3.1.29 Upgrade to ~> 3.1.30
Defined in Pipfile.lock
CVE-2022-24439 High severity

The stanza in pipfile reads:

        "gitpython": {
            "hashes": [
            "index": "pypi",
            "version": "==3.1.14"

I would suggest this is updated to 3.1.30 or later (even if at present this specific CVE can't be accessed because that might change!)
2023-01-11 09:31

developer   ~0004854

Thanks for pointing this out. As of the clone command is affected by this vulnerability, but that is not used by any of the scripts in, so it is probably irrelevant. Nevertheless this will be updated in the future.


2023-01-12 16:05

developer   ~0004855

Will be fixed once PR935 will be in


2023-02-07 13:59

developer   ~0004878

PR935 merge in

