Resource exhaustion in go-git - CVE-2023-49568

 

Resource exhaustion in go-git - CVE-2023-49568

Published: January 18, 2024


Vulnerability identifier: #VU85582
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-49568
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when handling responses from a Git server. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

go-git
Amazon Linux AMI
Ubuntu
Fedora
Red Hat OpenShift Builds
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
IBM Observability with Instana
IBM Concert Software
Multicluster GlobalHub
IBM MQ Operator
APEX Cloud Platform for Red Hat OpenShift
IBM Cloud Transformation Advisor
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Robotic Process Automation
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Supplied MQ Advanced Queue Manager Container images
OpenShift Serverless Client
Red Hat OpenShift Container Platform
Guardium Data Security Center (GDSC)
IBM Cloud Pak for Watson AIOps
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Storage Ceph
Robotic Process Automation for Cloud Pak
openshift-serverless-clients (Red Hat package)
amazon-ssm-agent
golang-github-go-git-go-git (Ubuntu package)
golang-github-git-5
Red Hat Ceph Storage

How to mitigate CVE-2023-49568

Install updates from vendor's website.

go-git - update to 5.11.0
Red Hat OpenShift Builds - update to 1.0.1
Red Hat OpenShift Serverless - update to 1.31.1
OpenShift Serverless Client - update to 1.31.1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.7.11, 2.8.5, 2.9.2
Guardium Data Security Center (GDSC) - update to 3.7.2
Red Hat Advanced Cluster Security for Kubernetes - update to 4.4.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.50, 4.12.51, 4.12.56, 4.13.33, 4.13.34, 4.14.11, 4.14.12, 4.14.22, 4.14.31, 4.15.0, 4.15.10, 4.15.18
IBM Observability with Instana - update to 265
IBM Concert Software - update to 1.0.1
Multicluster GlobalHub - update to 1.0.2
openshift-serverless-clients (Red Hat package) - update to 1.10.0-6.el8
IBM MQ Operator - addressed in versions 2.0.20, 3.1.1
APEX Cloud Platform for Red Hat OpenShift - update to 03.01.02.00
amazon-ssm-agent - update to 3.2.2222.0-1
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Cloud Pak for Watson AIOps - update to 4.4.1
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
DB2 on Cloud Pak for Data - update to 4.8.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.16.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0.1
golang-github-go-git-go-git (Ubuntu package) - addressed in versions 5.4.2-3ubuntu0.1~esm1, 5.4.2-4ubuntu0.24.04.3+esm2
golang-github-git-5 - update to 5.12.0-1.fc41
Storage Ceph - update to 7.1
Red Hat Ceph Storage - update to 7.1
IBM Supplied MQ Advanced Queue Manager Container images - addressed in versions 9.3.0.16-r2, 9.3.5.0-r2
IBM Robotic Process Automation - addressed in versions 21.0.7.15, 23.0.15
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.15

External References

Related Security Bulletins