Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-21613

Опубликовано: 06 янв. 2025
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.

An argument injection vulnerability was found in go-git. This flaw allows an attacker to set arbitrary values to git-upload-pack flags, leading to command or code execution, exposure of sensitive data, or other unintended behavior. This is only possible in configurations where the file transport protocol is being used.

Отчет

This vulnerability is rated as an Important severity because an argument injection has been discovered in go-git, where an attackers can manipulate git-upload-pack flags, potentially enabling command or code execution leads to an exposure of sensitive data or other unintended actions, this vulnerability occurs exclusively in configurations using the file transport protocol.

Меры по смягчению последствий

In cases where it is not possible to update to the latest version of go-git, it is recommended to enforce validation rules for values passed in the URL field.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-bundler-rhel9Affected
OpenShift API for Data Protectionoadp/oadp-mustgather-rhel8Affected
OpenShift Developer Tools and ServicesodoWill not fix
OpenShift Serverlessopenshift-serverless-1/client-kn-rhel8Affected
OpenShift Serverlessopenshift-serverless-1-func-utils-rhel8-containerAffected
OpenShift Serverlessopenshift-serverless-1/kn-cli-artifacts-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/multicluster-operators-subscription-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/submariner-rhel8-operatorAffected
Red Hat Ceph Storage 7rhceph/grafana-rhel9Affected
Red Hat Enterprise Linux 9grafanaAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2335888go-git: argument injection via the URL field

EPSS

Процентиль: 31%
0.00112
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
5 месяцев назад

go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.

CVSS3: 9.8
nvd
5 месяцев назад

go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.

CVSS3: 9.8
msrc
5 месяцев назад

Описание отсутствует

CVSS3: 9.8
debian
5 месяцев назад

go-git is a highly extensible git implementation library written in pu ...

suse-cvrf
5 месяцев назад

Security update for amazon-ssm-agent

EPSS

Процентиль: 31%
0.00112
Низкий

8.1 High

CVSS3