REDHAT-BUG-2335901: High severity go-git go-git vulnerability
go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2335901?
The severity of REDHAT-BUG-2335901 is classified as a denial of service (DoS) vulnerability.
How do I fix REDHAT-BUG-2335901?
To fix REDHAT-BUG-2335901, upgrade to go-git version 5.13 or later.
What versions are affected by REDHAT-BUG-2335901?
Go-git versions prior to 5.13 are affected by REDHAT-BUG-2335901.
What kind of attack does REDHAT-BUG-2335901 enable?
REDHAT-BUG-2335901 enables attackers to perform denial of service attacks.
Is there a patch available for REDHAT-BUG-2335901?
Yes, a patch is available in go-git version 5.13 and later.