VDB
RHSA-2024%3A0298
RHSA-2024%3A0298
PUBLISHED
CVSS 7.5 HIGH
A denial of service (DoS) vulnerability was found in the go library go-git. This issue may allow an attacker to perform denial of service attacks by providing specially crafted responses from a Git server, which can trigger resource exhaustion in go-git clients.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhacm2/endpoint-monitoring-rhel8-operator@sha256:4b713ac13d8a510f1fe9aad284690408e0c2f026b8380280f1a8b68fd178b93b_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | * |
| Red Hat | rhacm2/acm-search-indexer-rhel8@sha256:67874295d3ed742218b09ce34cd6c54157a8f19d7a14975c18177e5a8494311c_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | rhacm2/acm-search-indexer-rhel8@sha256:67874295d3ed742218b09ce34cd6c54157a8f19d7a14975c18177e5a8494311c_s390x |
| Red Hat | rhacm2/acm-governance-policy-framework-addon-rhel8@sha256:d277e101c7750a144cd3a5a3a342731161bf31d3fdd8c5c96f492ca6526cc839_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | * |
| Red Hat | rhacm2/acm-search-indexer-rhel8@sha256:67874295d3ed742218b09ce34cd6c54157a8f19d7a14975c18177e5a8494311c_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | * |
| Red Hat | rhacm2/observatorium-rhel8-operator@sha256:261d106384fff7dfa824da96c58bf52edc7c0892cb0497389bca8eb46d6f57f7_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | rhacm2/observatorium-rhel8-operator@sha256:261d106384fff7dfa824da96c58bf52edc7c0892cb0497389bca8eb46d6f57f7_arm64 |
| Red Hat | rhacm2/acm-prometheus-rhel8@sha256:e2c7821dfbbb966b6e9011e7140a93e6663cd769c0be2c2a8df4826475d2c5fd_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | * |
| Red Hat | rhacm2/multicluster-operators-application-rhel8@sha256:c96faf4ce709074e346c585b844c664de72945f9edd7ad646c72ea4d22cfa2aa_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | rhacm2/multicluster-operators-application-rhel8@sha256:c96faf4ce709074e346c585b844c664de72945f9edd7ad646c72ea4d22cfa2aa_amd64 |
| Red Hat | rhacm2/acm-governance-policy-framework-addon-rhel8@sha256:6b05a494e63d95c5c5173556f9781e6ed339833c71cc1ce459afbb8e35eb4dc8_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | rhacm2/acm-governance-policy-framework-addon-rhel8@sha256:6b05a494e63d95c5c5173556f9781e6ed339833c71cc1ce459afbb8e35eb4dc8_ppc64le |
| Red Hat | rhacm2/metrics-collector-rhel8@sha256:7b47618e9753bcc5ecec650653cd72de94ec8a14d7dccabfae146187d52fc984_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | * |
| Red Hat | rhacm2/klusterlet-addon-controller-rhel8@sha256:af4cc766a3e16fee5b83123b8f93c919e6322b41e3de426889cdf0614eb42c0f_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | * |
| Red Hat | rhacm2/acm-must-gather-rhel8@sha256:2a40e434a42298f400139343f2dd64b77b9ad24da5b3ee43cf58f3e9dcab1615_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | * |
| Red Hat | rhacm2/multicluster-operators-application-rhel8@sha256:209b8d33cb0c62478b8530b6cec2adc53b310384bd12c3f2dbff9f871f2c2778_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | * |
| Red Hat | rhacm2/acm-governance-policy-addon-controller-rhel8@sha256:80ffa43c41e804e1c6496c6b1b9348d259249ecba81d5fcc98346982c304beb8_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | rhacm2/acm-governance-policy-addon-controller-rhel8@sha256:80ffa43c41e804e1c6496c6b1b9348d259249ecba81d5fcc98346982c304beb8_amd64 |
| Red Hat | rhacm2/kube-rbac-proxy-rhel8@sha256:ff2663d1f2d4391ff5b590b6dd82147854f61674d25dbf84785b13f8f7ff7632_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | rhacm2/kube-rbac-proxy-rhel8@sha256:ff2663d1f2d4391ff5b590b6dd82147854f61674d25dbf84785b13f8f7ff7632_amd64 |
| Red Hat | rhacm2/acm-governance-policy-framework-addon-rhel8@sha256:6b05a494e63d95c5c5173556f9781e6ed339833c71cc1ce459afbb8e35eb4dc8_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | * |
| Red Hat | rhacm2/memcached-exporter-rhel8@sha256:af3d540636fd527ab414d4ef72bb82a9ebb8138284e58452a1839100663fa1a2_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | rhacm2/memcached-exporter-rhel8@sha256:af3d540636fd527ab414d4ef72bb82a9ebb8138284e58452a1839100663fa1a2_s390x |
| Red Hat | rhacm2/cluster-backup-rhel8-operator@sha256:688dbe8a6115186a59ca39f88619dd292d62d02f3dd6c2ba5078720845c125b7_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | * |
| Red Hat | rhacm2/multiclusterhub-rhel8@sha256:cbaae68ae8bd9e7a95a63a6cfdbea6aa4538c36922139017fdb9f4b59bfac53d_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | rhacm2/multiclusterhub-rhel8@sha256:cbaae68ae8bd9e7a95a63a6cfdbea6aa4538c36922139017fdb9f4b59bfac53d_amd64 |
| Red Hat | rhacm2/memcached-rhel8@sha256:26ac9315f8282e5fe2f4bcca0868ff2adc1a3dbe4ac4a14ae6b553ec7c187325_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | * |
| Red Hat | rhacm2/insights-client-rhel8@sha256:72af7ea1e6239dab6f7a282913113e7a12d3b208090131ffbba2ca2b76f82415_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | rhacm2/insights-client-rhel8@sha256:72af7ea1e6239dab6f7a282913113e7a12d3b208090131ffbba2ca2b76f82415_arm64 |
…and 330 more
Timeline
- Jan 18, 2024 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 12, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2024:0298 advisory
- https://access.redhat.com/security/updates/classification/#critical advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2258143 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2258165 issue
- https://issues.redhat.com/browse/ACM-8456 advisory
- https://issues.redhat.com/browse/ACM-8857 advisory
- https://issues.redhat.com/browse/ACM-8966 advisory
- https://issues.redhat.com/browse/ACM-9094 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0298.json advisory
- https://access.redhat.com/security/cve/CVE-2023-49568 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-49568 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-49568 advisory
- https://github.com/go-git/go-git/security/advisories/GHSA-mw99-9chc-xw7r advisory
- https://access.redhat.com/security/cve/CVE-2023-49569 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-49569 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-49569 advisory
- https://github.com/go-git/go-git/security/advisories/GHSA-449p-3h89-pw88 advisory