Resource exhaustion in go-git - CVE-2023-49568
Published: January 18, 2024
Vulnerability identifier: #VU85582
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-49568
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling responses from a Git server. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
go-git
Amazon Linux AMI
Ubuntu
Fedora
Red Hat OpenShift Builds
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
IBM Observability with Instana
IBM Concert Software
Multicluster GlobalHub
IBM MQ Operator
APEX Cloud Platform for Red Hat OpenShift
IBM Cloud Transformation Advisor
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Robotic Process Automation
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Supplied MQ Advanced Queue Manager Container images
OpenShift Serverless Client
Red Hat OpenShift Container Platform
Guardium Data Security Center (GDSC)
IBM Cloud Pak for Watson AIOps
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Storage Ceph
Robotic Process Automation for Cloud Pak
openshift-serverless-clients (Red Hat package)
amazon-ssm-agent
golang-github-go-git-go-git (Ubuntu package)
golang-github-git-5
Red Hat Ceph Storage
Amazon Linux AMI
Ubuntu
Fedora
Red Hat OpenShift Builds
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
IBM Observability with Instana
IBM Concert Software
Multicluster GlobalHub
IBM MQ Operator
APEX Cloud Platform for Red Hat OpenShift
IBM Cloud Transformation Advisor
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Robotic Process Automation
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Supplied MQ Advanced Queue Manager Container images
OpenShift Serverless Client
Red Hat OpenShift Container Platform
Guardium Data Security Center (GDSC)
IBM Cloud Pak for Watson AIOps
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Storage Ceph
Robotic Process Automation for Cloud Pak
openshift-serverless-clients (Red Hat package)
amazon-ssm-agent
golang-github-go-git-go-git (Ubuntu package)
golang-github-git-5
Red Hat Ceph Storage
How to mitigate CVE-2023-49568
Install updates from vendor's website.
go-git - update to 5.11.0
Red Hat OpenShift Builds - update to 1.0.1
Red Hat OpenShift Serverless - update to 1.31.1
OpenShift Serverless Client - update to 1.31.1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.7.11, 2.8.5, 2.9.2
Guardium Data Security Center (GDSC) - update to 3.7.2
Red Hat Advanced Cluster Security for Kubernetes - update to 4.4.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.50, 4.12.51, 4.12.56, 4.13.33, 4.13.34, 4.14.11, 4.14.12, 4.14.22, 4.14.31, 4.15.0, 4.15.10, 4.15.18
IBM Observability with Instana - update to 265
IBM Concert Software - update to 1.0.1
Multicluster GlobalHub - update to 1.0.2
openshift-serverless-clients (Red Hat package) - update to 1.10.0-6.el8
IBM MQ Operator - addressed in versions 2.0.20, 3.1.1
APEX Cloud Platform for Red Hat OpenShift - update to 03.01.02.00
amazon-ssm-agent - update to 3.2.2222.0-1
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Cloud Pak for Watson AIOps - update to 4.4.1
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
DB2 on Cloud Pak for Data - update to 4.8.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.16.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0.1
golang-github-go-git-go-git (Ubuntu package) - addressed in versions 5.4.2-3ubuntu0.1~esm1, 5.4.2-4ubuntu0.24.04.3+esm2
golang-github-git-5 - update to 5.12.0-1.fc41
Storage Ceph - update to 7.1
Red Hat Ceph Storage - update to 7.1
IBM Supplied MQ Advanced Queue Manager Container images - addressed in versions 9.3.0.16-r2, 9.3.5.0-r2
IBM Robotic Process Automation - addressed in versions 21.0.7.15, 23.0.15
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.15
Red Hat OpenShift Builds - update to 1.0.1
Red Hat OpenShift Serverless - update to 1.31.1
OpenShift Serverless Client - update to 1.31.1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.7.11, 2.8.5, 2.9.2
Guardium Data Security Center (GDSC) - update to 3.7.2
Red Hat Advanced Cluster Security for Kubernetes - update to 4.4.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.50, 4.12.51, 4.12.56, 4.13.33, 4.13.34, 4.14.11, 4.14.12, 4.14.22, 4.14.31, 4.15.0, 4.15.10, 4.15.18
IBM Observability with Instana - update to 265
IBM Concert Software - update to 1.0.1
Multicluster GlobalHub - update to 1.0.2
openshift-serverless-clients (Red Hat package) - update to 1.10.0-6.el8
IBM MQ Operator - addressed in versions 2.0.20, 3.1.1
APEX Cloud Platform for Red Hat OpenShift - update to 03.01.02.00
amazon-ssm-agent - update to 3.2.2222.0-1
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Cloud Pak for Watson AIOps - update to 4.4.1
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
DB2 on Cloud Pak for Data - update to 4.8.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.16.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0.1
golang-github-go-git-go-git (Ubuntu package) - addressed in versions 5.4.2-3ubuntu0.1~esm1, 5.4.2-4ubuntu0.24.04.3+esm2
golang-github-git-5 - update to 5.12.0-1.fc41
Storage Ceph - update to 7.1
Red Hat Ceph Storage - update to 7.1
IBM Supplied MQ Advanced Queue Manager Container images - addressed in versions 9.3.0.16-r2, 9.3.5.0-r2
IBM Robotic Process Automation - addressed in versions 21.0.7.15, 23.0.15
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.15
External References
Related Security Bulletins
- Multiple vulnerabilities in go-git
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.9
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.7
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- OpenShift Container Platform 4.13 update for go-git
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.8
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Serverless Client
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in Red Hat Multicluster GlobalHub
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Multiple vulnerabilities in Red Hat OpenShift Builds
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.4
- Fedora 41 update for golang-github-git-5
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in Red Hat Ceph Storage 7
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Storage Ceph
- Amazon Linux AMI update for amazon-ssm-agent
- Multiple vulnerabilities in IBM Robotic Process Automation
- Multiple vulnerabilities in IBM Concert Software
- Multiple vulnerabilities in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in Dell APEX Cloud Platform for Red Hat OpenShift
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Ubuntu update for golang-github-go-git-go-git