Improper neutralization of argument delimiters in a command in go-git - CVE-2025-21613

 

Improper neutralization of argument delimiters in a command in go-git - CVE-2025-21613

Published: January 29, 2025


Vulnerability identifier: #VU103421
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-21613
CWE-ID: CWE-88
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to improper input validation when handling URL field in arguments passed to the git-upload-pack command. A remote attacker can trick the victim into passing a specially crafted URL as a flag to the affected command and manipulate arguments for the git-upload-pack command, which can result in information disclosure.


Affected software

go-git
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Public Cloud Module
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Server for the Raspberry Pi
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Package Hub 15
Desktop Applications Module
openSUSE Leap
Ubuntu
IBM Concert Software
IBM Observability with Instana
IBM Cloud Pak for Security
APEX Cloud Platform for Red Hat OpenShift
Red Hat Advanced Cluster Security for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Cloud Pak for Business Automation
Guardium Data Security Center (GDSC)
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Robotic Process Automation for Cloud Pak
Business Automation Insights
OpenShift API for Data Protection (OADP)
OpenShift Service Mesh
amazon-ssm-agent
golang-github-go-git-go-git (Ubuntu package)
grafana (Red Hat package)
grafana
grafana-selinux
grafana-debuginfo
rime-schema-pinyin-simp
rime-schema-stenotype
rime-schema-wubi
rime-schema-luna-pinyin
rime-schema-wugniu
rime-schema-bopomofo
rime-schema-emoji
rime-schema-cantonese
rime-schema-soutzoe
rime-schema-double-pinyin
rime-schema-default
rime-schema-quick
rime-schema-custom
rime-schema-essay-simp
rime-schema-essay
rime-schema-ipa
rime-schema-scj
rime-schema-all
rime-schema-terra-pinyin
rime-schema-array
rime-schema-combo-pinyin
rime-schema-middle-chinese
rime-schema-prelude
rime-schema-cangjie
rime-schema-stroke
rime-schema-extra
Red Hat OpenShift Container Platform

How to mitigate CVE-2025-21613

Install updates from vendor's website.

go-git - update to 5.13.0
IBM Concert Software - update to 1.1.0
Guardium Data Security Center (GDSC) - update to 3.8.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.21, 23.0.20.2
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
IBM Observability with Instana - update to 289
OpenShift API for Data Protection (OADP) - update to 1.4.5
IBM Cloud Pak for Security - update to 1.11.2.0
OpenShift Service Mesh - addressed in versions 2.4.14, 2.5.8, 2.6.5
APEX Cloud Platform for Red Hat OpenShift - update to 03.01.02.00
amazon-ssm-agent - addressed in versions 3.3.1611.0-4.36.1, 3.3.1611.0-150000.5.20.1
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.4.8, 4.5.6, 4.6.2
Red Hat OpenShift Container Platform - addressed in versions 4.17.14, 4.17.16
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.1.1
golang-github-go-git-go-git (Ubuntu package) - addressed in versions 5.4.2-3ubuntu0.1~esm1, 5.4.2-4ubuntu0.24.04.3+esm2
grafana (Red Hat package) - addressed in versions 9.2.10-21.el8_10, 9.2.10-21.el9_4
grafana - update to 9.2.10-21.0.1
grafana-selinux - update to 9.2.10-21.0.1
grafana - addressed in versions 10.4.15-1.71.1, 10.4.15-150000.1.71.1, 10.4.15-150200.3.64.1
grafana-debuginfo - addressed in versions 10.4.15-150000.1.71.1, 10.4.15-150200.3.64.1
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF005, 25.0.0-IF001
rime-schema-pinyin-simp - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-stenotype - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-wubi - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-luna-pinyin - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-wugniu - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-bopomofo - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-emoji - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-cantonese - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-soutzoe - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-double-pinyin - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-default - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-quick - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-custom - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-essay-simp - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-essay - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-ipa - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-scj - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-all - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-terra-pinyin - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-array - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-combo-pinyin - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-middle-chinese - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-prelude - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-cangjie - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-stroke - update to 20230603+git.5fdd2d6-150600.3.8.1
rime-schema-extra - update to 20230603+git.5fdd2d6-150600.3.8.1

External References

Related Security Bulletins