Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-49569

Опубликовано: 12 янв. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9.8

Описание

A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, remote code execution could be achieved. Applications are only affected if they are using the ChrootOS https://pkg.go.dev/github.com/go-git/go-billy/v5/osfs#ChrootOS , which is the default when using "Plain" versions of Open and Clone funcs (e.g. PlainClone). Applications using BoundOS https://pkg.go.dev/github.com/go-git/go-billy/v5/osfs#BoundOS  or in-memory filesystems are not affected by this issue. This is a go-git implementation issue and does not affect the upstream git cli.

РелизСтатусПримечание
bionic

DNE

devel

not-affected

5.16.2-1
esm-apps/jammy

released

5.4.2-3ubuntu0.1~esm1
esm-apps/noble

released

5.4.2-4ubuntu0.24.04.3+esm2
esm-apps/resolute

not-affected

5.16.2-1
esm-infra/focal

DNE

focal

DNE

jammy

needed

lunar

ignored

end of life, was needs-triage
mantic

ignored

end of life, was needs-triage

Показывать по

EPSS

Процентиль: 72%
0.01523
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.1
redhat
больше 2 лет назад

A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, remote code execution could be achieved. Applications are only affected if they are using the ChrootOS https://pkg.go.dev/github.com/go-git/go-billy/v5/osfs#ChrootOS , which is the default when using "Plain" versions of Open and Clone funcs (e.g. PlainClone). Applications using BoundOS https://pkg.go.dev/github.com/go-git/go-billy/v5/osfs#BoundOS  or in-memory filesystems are not affected by this issue. This is a go-git implementation issue and does not affect the upstream git cli.

CVSS3: 9.8
nvd
больше 2 лет назад

A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, remote code execution could be achieved. Applications are only affected if they are using the ChrootOS https://pkg.go.dev/github.com/go-git/go-billy/v5/osfs#ChrootOS , which is the default when using "Plain" versions of Open and Clone funcs (e.g. PlainClone). Applications using BoundOS https://pkg.go.dev/github.com/go-git/go-billy/v5/osfs#BoundOS  or in-memory filesystems are not affected by this issue. This is a go-git implementation issue and does not affect the upstream git cli.

CVSS3: 9.8
msrc
почти 2 года назад

Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

CVSS3: 9.8
debian
больше 2 лет назад

A path traversal vulnerability was discovered in go-git versions prior ...

CVSS3: 9.8
github
больше 2 лет назад

Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

EPSS

Процентиль: 72%
0.01523
Низкий

9.8 Critical

CVSS3