发布于3月6日3月6日 Members Red Hat: CVE-2025-21613: go-git: argument injection via the URL field (Multiple Advisories) Severity 8 CVSS (AV:N/AC:H/Au:N/C:C/I:C/A:C) Published 01/06/2025 Created 01/23/2025 Added 01/22/2025 Modified 01/24/2025 Description go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0. Solution(s) redhat-upgrade-grafana redhat-upgrade-grafana-debuginfo redhat-upgrade-grafana-debugsource redhat-upgrade-grafana-selinux References CVE-2025-21613 RHSA-2025:0401 RHSA-2025:0662
参与讨论
你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。