Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-49568

Опубликовано: 24 дек. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Applications using only the in-memory filesystem supported by go-git are not affected by this vulnerability. This is a go-git implementation issue and does not affect the upstream git cli.

A denial of service (DoS) vulnerability was found in the go library go-git. This issue may allow an attacker to perform denial of service attacks by providing specially crafted responses from a Git server, which can trigger resource exhaustion in go-git clients.

Отчет

This problem only affects the go implementation and not the original git cli code. Applications using only in-memory filesystems are not affected by this issue. Clients should be limited to connect to only trusted git servers to reduce the risk of compromise.

Меры по смягчению последствий

In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesodoWill not fix
Red Hat Advanced Cluster Management for Kubernetes 2hub-of-hubs-gitopsNot affected
Red Hat Advanced Cluster Management for Kubernetes 2multicluster-engineAffected
Red Hat Advanced Cluster Management for Kubernetes 2multicluster-engine-assisted-installer-reporterWill not fix
Red Hat Advanced Cluster Management for Kubernetes 2multicluster-engine-assisted-serviceWill not fix
Red Hat Advanced Cluster Management for Kubernetes 2multicluster-globalhub-grafanaAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/cluster-curator-controller-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/clusterlifecycle-state-metrics-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/multicluster-operators-subscription-release-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/openshift-hive-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2258165go-git: Maliciously crafted Git server replies can cause DoS on go-git clients

EPSS

Процентиль: 36%
0.00153
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 лет назад

A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Applications using only the in-memory filesystem supported by go-git are not affected by this vulnerability. This is a go-git implementation issue and does not affect the upstream git cli.

CVSS3: 7.5
nvd
около 2 лет назад

A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Applications using only the in-memory filesystem supported by go-git are not affected by this vulnerability. This is a go-git implementation issue and does not affect the upstream git cli.

CVSS3: 7.5
msrc
больше 1 года назад

Maliciously crafted Git server replies can cause DoS on go-git clients

CVSS3: 7.5
debian
около 2 лет назад

A denial of service (DoS) vulnerability was discovered in go-git versi ...

CVSS3: 7.5
github
около 2 лет назад

Maliciously crafted Git server replies can cause DoS on go-git clients

EPSS

Процентиль: 36%
0.00153
Низкий

7.5 High

CVSS3

Уязвимость CVE-2023-49568