CVE-2023-49568: Maliciously crafted Git server replies can cause DoS on go-git clients
Impact A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients.
Applications using only the in-memory filesystem supported by go-git are not affected by this vulnerability. This is a go-git implementation issue and does not affect the upstream git cli.
Patches Users running versions of go-git from v4 and above are recommended to upgrade to v5.11 in order to mitigate this vulnerability.
Workarounds In cases where a bump to the latest version of go-git is not possible, we recommend limiting its use to only trust-worthy Git servers.
Credit Thanks to Ionut Lalu for responsibly disclosing this vulnerability to us.
References - GHSA-mw99-9chc-xw7r
Other sources
A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients.
Applications using only the in-memory filesystem supported by go-git are not affected by this vulnerability. This is a go-git implementation issue and does not affect the upstream git cli.
— NVD
go-git is vulnerable to a denial of service, caused by improper input validation. By sending a specially crafted responses from a Git server, a remote attacker could exploit this vulnerability to trigger resource exhaustion in go-git clients, and results in a denial of service conditoin.
— IBM
Maliciously crafted Git server replies can cause DoS on go-git clients
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/go-git/go-git/v5to a version that resolves this vulnerability.Fixed in 5.11.0 - Upgrade
Upgrade
redhat/go-gitto a version that resolves this vulnerability.Fixed in 5.11 - Upgrade
Upgrade
go-gitto a version that resolves this vulnerability.Fixed in v5.11 - Compensating control
If upgrading to v5.11 is not possible, limit go-git usage to only trustworthy Git servers (applications using only the in-memory filesystem supported by go-git are not affected).
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49568?
CVE-2023-49568 is classified as a denial of service (DoS) vulnerability.
How do I fix CVE-2023-49568?
To resolve CVE-2023-49568, upgrade to go-git version 5.11 or later.
Which versions of go-git are affected by CVE-2023-49568?
CVE-2023-49568 affects go-git versions before v5.11.
Can CVE-2023-49568 impact my application?
Yes, CVE-2023-49568 can lead to resource exhaustion resulting in a denial of service for applications using the affected versions of go-git.
What software products are affected by CVE-2023-49568?
CVE-2023-49568 impacts IBM Db2 on Cloud Pak for Data and multiple versions of go-git prior to v5.11.