go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:0401 https://access.redhat.com/errata/RHSA-2025:0401
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:0662 https://access.redhat.com/errata/RHSA-2025:0662
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2025:0654 https://access.redhat.com/errata/RHSA-2025:0654
This issue has been addressed in the following products: Red Hat Advanced Cluster Security 4.6 Via RHSA-2025:0907 https://access.redhat.com/errata/RHSA-2025:0907
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2025:1119 https://access.redhat.com/errata/RHSA-2025:1119
This issue has been addressed in the following products: Red Hat Advanced Cluster Security 4.5 Via RHSA-2025:1334 https://access.redhat.com/errata/RHSA-2025:1334
This issue has been addressed in the following products: Red Hat Advanced Cluster Security 4.4 Via RHSA-2025:1468 https://access.redhat.com/errata/RHSA-2025:1468
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.18 Via RHSA-2024:6122 https://access.redhat.com/errata/RHSA-2024:6122
This issue has been addressed in the following products: Red Hat OpenStack Platform 16.2 Via RHSA-2025:1869 https://access.redhat.com/errata/RHSA-2025:1869
This issue has been addressed in the following products: Red Hat OpenStack Platform 17.1 for RHEL 9 Via RHSA-2025:1870 https://access.redhat.com/errata/RHSA-2025:1870
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2025:1704 https://access.redhat.com/errata/RHSA-2025:1704
This issue has been addressed in the following products: Red Hat OpenShift GitOps 1.14 Via RHSA-2025:3069 https://access.redhat.com/errata/RHSA-2025:3069