CVE Vulnerabilities

CVE-2023-49568

Published: Jan 12, 2024 | Modified: Jan 22, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients.

Applications using only the in-memory filesystem supported by go-git are not affected by this vulnerability. This is a go-git implementation issue and does not affect the upstream git cli.

Affected Software

Name Vendor Start Version End Version
Go-git Go-git_project 4.0.0 (including) 5.11.0 (excluding)
Multicluster-globalhub 1.0 for RHEL 8 RedHat multicluster-globalhub/multicluster-globalhub-grafana-rhel8:v1.0.2-4 *
OPENSHIFT-BUILDS-1.0-RHEL-8 RedHat openshift-builds/openshift-builds-controller-rhel8:v1.0.1-4 *
OPENSHIFT-BUILDS-1.0-RHEL-8 RedHat openshift-builds/openshift-builds-git-cloner-rhel8:v1.0.1-4 *
OPENSHIFT-BUILDS-1.0-RHEL-8 RedHat openshift-builds/openshift-builds-image-bundler-rhel8:v1.0.1-4 *
OPENSHIFT-BUILDS-1.0-RHEL-8 RedHat openshift-builds/openshift-builds-image-processing-rhel8:v1.0.1-4 *
OPENSHIFT-BUILDS-1.0-RHEL-8 RedHat openshift-builds/openshift-builds-operator-bundle:v1.0.1-11 *
OPENSHIFT-BUILDS-1.0-RHEL-8 RedHat openshift-builds/openshift-builds-rhel8-operator:v1.0.1-6 *
OPENSHIFT-BUILDS-1.0-RHEL-8 RedHat openshift-builds/openshift-builds-waiters-rhel8:v1.0.1-4 *
OPENSHIFT-BUILDS-1.0-RHEL-8 RedHat openshift-builds/openshift-builds-webhook-rhel8:v1.0.1-4 *
Openshift Serverless 1 on RHEL 8 RedHat openshift-serverless-clients-0:1.10.0-6.el8 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/acm-governance-policy-addon-controller-rhel8:v2.7.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/acm-governance-policy-framework-addon-rhel8:v2.7.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/acm-grafana-rhel8:v2.7.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/acm-must-gather-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/acm-operator-bundle:v2.7.11-14 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/acm-prometheus-config-reloader-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/acm-prometheus-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/acm-search-indexer-rhel8:v2.7.11-4 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/acm-search-v2-api-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/acm-search-v2-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/acm-volsync-addon-controller-rhel8:v2.7.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/cert-policy-controller-rhel8:v2.7.11-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/cluster-backup-rhel8-operator:v2.7.11-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/config-policy-controller-rhel8:v2.7.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/console-rhel8:v2.7.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/endpoint-monitoring-rhel8-operator:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/governance-policy-propagator-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/grafana-dashboard-loader-rhel8:v2.7.11-4 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/iam-policy-controller-rhel8:v2.7.11-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/insights-client-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/insights-metrics-rhel8:v2.7.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/klusterlet-addon-controller-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/kube-rbac-proxy-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/kube-state-metrics-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/memcached-exporter-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/memcached-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/metrics-collector-rhel8:v2.7.11-4 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/multicloud-integrations-rhel8:v2.7.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/multiclusterhub-rhel8:v2.7.11-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/multicluster-observability-rhel8-operator:v2.7.11-4 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/multicluster-operators-application-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/multicluster-operators-channel-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/multicluster-operators-subscription-rhel8:v2.7.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/node-exporter-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/observatorium-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/observatorium-rhel8-operator:v2.7.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/prometheus-alertmanager-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/prometheus-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/rbac-query-proxy-rhel8:v2.7.11-4 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/search-collector-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/submariner-addon-rhel8:v2.7.11-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/thanos-receive-controller-rhel8:v2.7.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 RedHat rhacm2/thanos-rhel8:v2.7.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.8 for RHEL 8 RedHat rhacm2/multicluster-operators-subscription-rhel8:v2.8.5-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 RedHat rhacm2/multicluster-operators-subscription-rhel8:v2.9.2-2 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-central-db-rhel8:4.4.0-9 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-main-rhel8:4.4.0-17 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-rhel8-operator:4.4.0-9 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-roxctl-rhel8:4.4.0-9 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-scanner-db-rhel8:4.4.0-11 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-scanner-db-slim-rhel8:4.4.0-2 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-scanner-rhel8:4.4.0-11 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-scanner-slim-rhel8:4.4.0-11 *
Red Hat Ceph Storage 7.1 RedHat ceph-2:18.2.1-194.el9cp *
Red Hat OpenShift Container Platform 4.12 RedHat openshift4/ose-ansible-operator:v4.12.0-202402081808.p0.g0bd975e.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.12 RedHat openshift4/ose-helm-operator:v4.12.0-202402081808.p0.g0bd975e.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.12 RedHat openshift4/ose-operator-sdk-rhel8:v4.12.0-202402081808.p0.g0bd975e.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.12 RedHat openshift4/ose-operator-lifecycle-manager:v4.12.0-202402111607.p0.g9dd28b4.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.12 RedHat openshift4/ose-operator-registry:v4.12.0-202402111607.p0.g9dd28b4.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.12 RedHat redhat/redhat-operator-index:v4.12.0-202402111607.p0.g9dd28b4.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.12 RedHat openshift4/ose-olm-rukpak-rhel8:v4.12.0-202402161937.p0.gf219ce7.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.12 RedHat openshift4/oc-mirror-plugin-rhel8:v4.12.0-202404171248.p0.g3f39dc6.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.13 RedHat openshift4/ose-ansible-operator:v4.13.0-202402020908.p0.g01bfabb.assembly.stream *
Red Hat OpenShift Container Platform 4.13 RedHat openshift4/ose-helm-operator:v4.13.0-202402020908.p0.g01bfabb.assembly.stream *
Red Hat OpenShift Container Platform 4.13 RedHat openshift4/ose-operator-sdk-rhel8:v4.13.0-202402071637.p0.g01bfabb.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.13 RedHat openshift4/ose-olm-rukpak-rhel8:v4.13.0-202402070238.p0.gaf47118.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.13 RedHat openshift4/ose-operator-lifecycle-manager:v4.13.0-202402081808.p0.g4cc5232.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.13 RedHat openshift4/ose-operator-registry:v4.13.0-202402081808.p0.g4cc5232.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.13 RedHat openshift4/oc-mirror-plugin-rhel8:v4.13.0-202404200313.p0.g02367d7.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.14 RedHat openshift4/ose-ansible-operator:v4.14.0-202401301709.p0.g0f0d1b2.assembly.stream *
Red Hat OpenShift Container Platform 4.14 RedHat openshift4/ose-helm-operator:v4.14.0-202401301709.p0.g0f0d1b2.assembly.stream *
Red Hat OpenShift Container Platform 4.14 RedHat openshift4/ose-operator-sdk-rhel8:v4.14.0-202401301709.p0.g0f0d1b2.assembly.stream *
Red Hat OpenShift Container Platform 4.14 RedHat openshift4/ose-olm-catalogd-rhel8:v4.14.0-202401292111.p0.ga333cb0.assembly.stream *
Red Hat OpenShift Container Platform 4.14 RedHat openshift4/ose-olm-operator-controller-rhel8:v4.14.0-202401292111.p0.gfb6fb27.assembly.stream *
Red Hat OpenShift Container Platform 4.14 RedHat openshift4/ose-operator-lifecycle-manager:v4.14.0-202402010409.p0.gb831504.assembly.stream *
Red Hat OpenShift Container Platform 4.14 RedHat openshift4/ose-operator-registry:v4.14.0-202402010409.p0.gb831504.assembly.stream *
Red Hat OpenShift Container Platform 4.14 RedHat redhat/redhat-operator-index:v4.14.0-202402010409.p0.gb831504.assembly.stream *
Red Hat OpenShift Container Platform 4.14 RedHat openshift4/ose-olm-rukpak-rhel8:v4.14.0-202402060410.p0.g2287fb2.assembly.stream *
Red Hat OpenShift Container Platform 4.14 RedHat openshift4/oc-mirror-plugin-rhel8:v4.14.0-202404161544.p0.ga0733c1.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.14 RedHat openshift4/ose-tools-rhel8:v4.14.0-202406180839.p0.gaa6e2f2.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.15 RedHat openshift4/ose-tools-rhel8:v4.15.0-202406101406.p0.g44edfb5.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.15 RedHat openshift4/oc-mirror-plugin-rhel9:v4.15.0-202404161612.p0.g85c8f6f.assembly.stream.el9 *
Red Hat OpenShift GitOps 1.10 RedHat openshift-gitops-1/argocd-rhel8:v1.10.2-2 *
Red Hat OpenShift GitOps 1.10 RedHat openshift-gitops-1/argo-rollouts-rhel8:v1.10.2-2 *
Red Hat OpenShift GitOps 1.10 RedHat openshift-gitops-1/console-plugin-rhel8:v1.10.2-2 *
Red Hat OpenShift GitOps 1.10 RedHat openshift-gitops-1/dex-rhel8:v1.10.2-2 *
Red Hat OpenShift GitOps 1.10 RedHat openshift-gitops-1/gitops-operator-bundle:v1.10.2-2 *
Red Hat OpenShift GitOps 1.10 RedHat openshift-gitops-1/gitops-rhel8:v1.10.2-2 *
Red Hat OpenShift GitOps 1.10 RedHat openshift-gitops-1/gitops-rhel8-operator:v1.10.2-2 *
Red Hat OpenShift GitOps 1.10 RedHat openshift-gitops-1/kam-delivery-rhel8:v1.10.2-2 *
Red Hat OpenShift GitOps 1.10 RedHat openshift-gitops-1/must-gather-rhel8:v1.10.2-2 *
Red Hat OpenShift GitOps 1.9 RedHat openshift-gitops-1/argocd-rhel8:v1.9.4-1 *
Red Hat OpenShift GitOps 1.9 RedHat openshift-gitops-1/argo-rollouts-rhel8:v1.9.4-1 *
Red Hat OpenShift GitOps 1.9 RedHat openshift-gitops-1/console-plugin-rhel8:v1.9.4-1 *
Red Hat OpenShift GitOps 1.9 RedHat openshift-gitops-1/dex-rhel8:v1.9.4-1 *
Red Hat OpenShift GitOps 1.9 RedHat openshift-gitops-1/gitops-operator-bundle:v1.9.4-1 *
Red Hat OpenShift GitOps 1.9 RedHat openshift-gitops-1/gitops-rhel8:v1.9.4-1 *
Red Hat OpenShift GitOps 1.9 RedHat openshift-gitops-1/gitops-rhel8-operator:v1.9.4-1 *
Red Hat OpenShift GitOps 1.9 RedHat openshift-gitops-1/kam-delivery-rhel8:v1.9.4-1 *
Red Hat OpenShift GitOps 1.9 RedHat openshift-gitops-1/must-gather-rhel8:v1.9.4-1 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/client-kn-rhel8:1.10.0-5 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-controller-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-in-memory-channel-controller-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-istio-controller-rhel8:1.10.0-5 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-controller-rhel8:1.10.0-3 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-dispatcher-rhel8:1.10.0-3 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-post-install-rhel8:1.10.0-3 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-receiver-rhel8:1.10.0-3 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-webhook-rhel8:1.10.0-3 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-mtbroker-filter-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-mtbroker-ingress-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-mtchannel-broker-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-mtping-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-storage-version-migration-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/eventing-webhook-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/func-utils-rhel8:1.31.1-2 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/ingress-rhel8-operator:1.31.1-2 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/knative-rhel8-operator:1.31.1-2 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/kn-cli-artifacts-rhel8:1.10.0-3 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/kourier-control-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/net-istio-controller-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/net-istio-webhook-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serverless-operator-bundle:1.31.1-1 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serverless-rhel8-operator:1.31.1-2 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serving-activator-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serving-autoscaler-hpa-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serving-autoscaler-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serving-controller-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serving-domain-mapping-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serving-domain-mapping-webhook-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serving-queue-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serving-storage-version-migration-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/serving-webhook-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1/svls-must-gather-rhel8:1.31.1-2 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1-tech-preview/eventing-istio-controller-rhel8:1.10.0-5 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1-tech-preview/knative-client-plugin-event-sender-rhel8:1.10.0-4 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1-tech-preview/logic-swf-builder-rhel8:1.31.0-5 *
RHOSS-1.31-RHEL-8 RedHat openshift-serverless-1-tech-preview/logic-swf-devmode-rhel8:1.31.0-4 *
Golang-github-go-git-go-git Ubuntu bionic *
Golang-github-go-git-go-git Ubuntu lunar *
Golang-github-go-git-go-git Ubuntu mantic *
Golang-github-go-git-go-git Ubuntu trusty *
Golang-github-go-git-go-git Ubuntu xenial *

References