Lucene search

K
githubGitHub Advisory DatabaseGHSA-MW99-9CHC-XW7R
HistoryDec 27, 2023 - 3:06 p.m.

Maliciously crafted Git server replies can cause DoS on go-git clients

2023-12-2715:06:52
CWE-20
GitHub Advisory Database
github.com
44
vulnerability
go-git
dos
git server
resource exhaustion
upgrade
workaround
disclosure

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

17.0%

Impact

A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients.

Applications using only the in-memory filesystem supported by go-git are not affected by this vulnerability.
This is a go-git implementation issue and does not affect the upstream git cli.

Patches

Users running versions of go-git from v4 and above are recommended to upgrade to v5.11 in order to mitigate this vulnerability.

Workarounds

In cases where a bump to the latest version of go-git is not possible, we recommend limiting its use to only trust-worthy Git servers.

Credit

Thanks to Ionut Lalu for responsibly disclosing this vulnerability to us.

References

Affected configurations

Vulners
Node
src-dgo-git.v4Range4.7.1
OR
go-gitgo-gitRange4.0.05.11.0
VendorProductVersionCPE
src-dgo-git.v4*cpe:2.3:a:src-d:go-git.v4:*:*:*:*:*:*:*:*
go-gitgo-git*cpe:2.3:a:go-git:go-git:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

17.0%