CVE-2023-49568
ADVISORY - githubSummary
Impact
A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients.
Applications using only the in-memory filesystem supported by go-git are not affected by this vulnerability.
This is a go-git implementation issue and does not affect the upstream git cli.
Patches
Users running versions of go-git from v4 and above are recommended to upgrade to v5.11 in order to mitigate this vulnerability.
Workarounds
In cases where a bump to the latest version of go-git is not possible, we recommend limiting its use to only trust-worthy Git servers.
Credit
Thanks to Ionut Lalu for responsibly disclosing this vulnerability to us.
References
Common Weakness Enumeration (CWE)
Improper Input Validation
Improper Input Validation
Uncontrolled Resource Consumption
NIST
3.9
CVSS SCORE
7.5highGitHub
3.9
CVSS SCORE
7.5highAlpine
-
Debian
-
Ubuntu
3.9
CVSS SCORE
7.5mediumGoLang
-
Amazon
-
CVSS SCORE
N/AhighAmazon
-
CVSS SCORE
N/AhighAmazon
-
CVSS SCORE
N/AhighRed Hat
3.9
CVSS SCORE
7.5highChainguard
CGA-3649-h3j9-rvx6
-
Chainguard
CGA-386m-pr6v-7wq2
-
Chainguard
CGA-453h-pgg7-xw3r
-
Chainguard
CGA-486r-p4fq-q959
-
Chainguard
CGA-4x69-xmvh-89mw
-
Chainguard
CGA-54g8-jwm3-m68x
-
Chainguard
CGA-6xm2-x4rj-xvgx
-
Chainguard
CGA-7897-g922-6qf2
-
Chainguard
CGA-7pqw-3cfv-mfrc
-
Chainguard
CGA-824q-mm8q-fg8w
-
Chainguard
CGA-8678-f34j-w23h
-
Chainguard
CGA-8846-v282-jc4f
-
Chainguard
CGA-948w-qmmc-gw76
-
Chainguard
CGA-f2qm-m2cx-qx6r
-
Chainguard
CGA-f69f-9576-qmxm
-
Chainguard
CGA-ff45-jpq8-jw8c
-
Chainguard
CGA-frpf-j89x-wfhc
-
Chainguard
CGA-fxq8-hgpw-6v78
-
Chainguard
CGA-jp77-49rg-8xwx
-
Chainguard
CGA-jx4h-vvh9-5j73
-
Chainguard
CGA-m6qq-79rg-rjwv
-
Chainguard
CGA-p2w5-4v25-589r
-
Chainguard
CGA-p5r8-cfv9-cmhc
-
Chainguard
CGA-p83x-8387-c6fj
-
Chainguard
CGA-q7f9-729r-99v3
-
Chainguard
CGA-rwg5-6pf6-v3px
-
Chainguard
CGA-v4xq-f4rj-pr4r
-
Chainguard
CGA-v9fj-w7f9-p53h
-
Chainguard
CGA-vrx4-hf5c-hgv8
-
Chainguard
CGA-wgvq-wm85-q9vx
-
Chainguard
CGA-wwh6-vmmm-85jv
-
Chainguard
CGA-xgmc-87vw-749v
-
Chainguard
CGA-xp2m-fxr2-rf4v
-