Path traversal in go-git - CVE-2023-49569

 

Path traversal in go-git - CVE-2023-49569

Published: January 18, 2024


Vulnerability identifier: #VU85583
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-49569
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can overwrite arbitrary files on the system. Applications are only affected if they are using the ChrootOS, which is the default when using "Plain" versions of Open and Clone funcs (e.g. PlainClone).


Affected software

go-git
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Ubuntu
Fedora
Red Hat OpenShift Builds
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
IBM Observability with Instana
IBM Concert Software
Multicluster GlobalHub
Netcool Operations Insight
IBM MQ Operator
APEX Cloud Platform for Red Hat OpenShift
IBM Cloud Transformation Advisor
IBM Watson Assistant for IBM Cloud Pak for Data
Ceph
IBM Robotic Process Automation
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Supplied MQ Advanced Queue Manager Container images
OpenShift Serverless Client
Red Hat OpenShift Container Platform
Guardium Data Security Center (GDSC)
Terraform Provider for PowerStore
IBM Cloud Pak for Watson AIOps
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Storage Ceph
Robotic Process Automation for Cloud Pak
openshift-serverless-clients (Red Hat package)
amazon-ssm-agent
golang-github-go-git-go-git (Ubuntu package)
golang-github-git-5
ceph-ansible (Red Hat package)
Red Hat Ceph Storage

How to mitigate CVE-2023-49569

Install update from vendor's website.

go-git - update to 5.11.0
Red Hat OpenShift Builds - addressed in versions 1.0.1, 1.1.0
Red Hat OpenShift Serverless - update to 1.31.1
OpenShift Serverless Client - update to 1.31.1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.7.11, 2.8.5, 2.9.2
Guardium Data Security Center (GDSC) - update to 3.7.2
Red Hat Advanced Cluster Security for Kubernetes - update to 4.3.6
Red Hat OpenShift Container Platform - addressed in versions 4.12.50, 4.12.51, 4.12.56, 4.13.33, 4.13.34, 4.14.11, 4.14.12, 4.14.22, 4.15.0, 4.15.37
IBM Observability with Instana - update to 265
IBM Concert Software - update to 1.0.1
Multicluster GlobalHub - update to 1.0.2
Terraform Provider for PowerStore - update to 1.1.2
Netcool Operations Insight - update to 1.6.12
openshift-serverless-clients (Red Hat package) - update to 1.10.0-6.el8
IBM MQ Operator - addressed in versions 2.0.20, 3.1.1
APEX Cloud Platform for Red Hat OpenShift - update to 03.01.02.00
amazon-ssm-agent - update to 3.2.2222.0-1
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Cloud Pak for Watson AIOps - update to 4.4.1
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
DB2 on Cloud Pak for Data - update to 4.8.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.16.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0.1
Red Hat Ceph Storage - addressed in versions 5.3, 7.1
golang-github-go-git-go-git (Ubuntu package) - addressed in versions 5.4.2-3ubuntu0.1~esm1, 5.4.2-4ubuntu0.24.04.3+esm2
golang-github-git-5 - update to 5.12.0-1.fc41
ceph-ansible (Red Hat package) - update to 6.0.28.8-1.el8cp
Storage Ceph - update to 7.1
IBM Supplied MQ Advanced Queue Manager Container images - addressed in versions 9.3.0.16-r2, 9.3.5.0-r2
Ceph - addressed in versions 16.2.10-266.el8cp, 16.2.10-266.el9cp, 17.2.6-216.el8cp, 17.2.6-216.el9cp
IBM Robotic Process Automation - addressed in versions 21.0.7.15, 23.0.15
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.15

External References

Related Security Bulletins