go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.
CVSS Details
- CVSS 4.0 Base Score: 9.2 (CRITICAL)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear)
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade grafana-selinuxUpgrade grafana | Jan 21, 2025 | Jan 6, 2025 |
| Amazon Linux Ami 2 | — | Upgrade amazon-ssm-agent | Feb 5, 2025 | Jan 6, 2025 |
| Amazon_linux_2023 | — | Upgrade amazon-ssm-agent | Feb 17, 2025 | Jan 6, 2025 |
| Debian | — | Upgrade golang-github-go-git-go-git | May 15, 2025 | Jan 6, 2025 |
| Oracle_linux | — | Upgrade grafanaUpgrade grafana-selinux | Jan 20, 2025 | Jan 6, 2025 |
| Redhat_linux | — | Upgrade grafanaUpgrade grafana-debuginfoUpgrade grafana-debugsourceUpgrade grafana-selinux | Jan 22, 2025 | Jan 6, 2025 |
| Rocky_linux | — | Upgrade grafana-selinuxUpgrade grafana-debugsourceUpgrade grafanaUpgrade grafana-debuginfo | Feb 14, 2025 | Jan 6, 2025 |
| Suse | — | Upgrade rime-schema-bopomofoUpgrade rime-schema-strokeUpgrade rime-schema-pinyin-simpUpgrade rime-schema-soutzoeUpgrade rime-schema-middle-chineseUpgrade rime-schema-luna-pinyinUpgrade rime-schema-terra-pinyinUpgrade govulncheck-vulndbUpgrade rime-schema-allUpgrade grafanaUpgrade rime-schema-wugniuUpgrade rime-schema-cantoneseUpgrade amazon-ssm-agentUpgrade rime-schema-ipaUpgrade rime-schema-wubiUpgrade rime-schema-combo-pinyinUpgrade rime-schema-essay-simpUpgrade rime-schema-quickUpgrade rime-schema-scjUpgrade rime-schema-defaultUpgrade rime-schema-preludeUpgrade rime-schema-arrayUpgrade trivyUpgrade rime-schema-emojiUpgrade rime-schema-double-pinyinUpgrade rime-schema-stenotypeUpgrade rime-schema-cangjieUpgrade rime-schema-essayUpgrade rime-schema-customUpgrade rime-schema-extra | Jan 13, 2025 | Jan 6, 2025 |
| Ubuntu | — | Upgrade golang-github-go-git-go-git-dev (Ubuntu Pro)Upgrade go-git (Ubuntu Pro) | Mar 13, 2026 | Jan 6, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub