VDB
RHSA-2025%3A1869
RHSA-2025%3A1869
PUBLISHED
CVSS 8.100000381469727 HIGH
An argument injection vulnerability was found in go-git. This flaw allows an attacker to set arbitrary values to git-upload-pack flags, leading to command or code execution, exposure of sensitive data, or other unintended behavior. This is only possible in configurations where the file transport protocol is being used.
Risk Scores
CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhosp-rhel8/osp-director-operator@sha256:f688739a10ab007f7a8a0de75327d56a67a9da1182d9a06130d75e0b57617da9_amd64 as a component of Red Hat OpenStack Platform 16.2 | * |
| Red Hat | rhosp-rhel8/osp-director-agent@sha256:2732885be77c420c09d4b193256f98f791fbaf68b0df53ce74a075312d5909be_amd64 as a component of Red Hat OpenStack Platform 16.2 | * |
| Red Hat | rhosp-rhel8/osp-director-operator-bundle@sha256:65acbffc986354da1ce64aff2f02fb32b91a307852317b50516adc19f2c75c6e_amd64 as a component of Red Hat OpenStack Platform 16.2 | rhosp-rhel8/osp-director-operator-bundle@sha256:65acbffc986354da1ce64aff2f02fb32b91a307852317b50516adc19f2c75c6e_amd64 |
| Red Hat | rhosp-rhel8/osp-director-downloader@sha256:d2a3d5f1197063fdfe3243eaf9ecb599e77201a06a589b9021845e4fd1d3473c_amd64 as a component of Red Hat OpenStack Platform 16.2 | rhosp-rhel8/osp-director-downloader@sha256:d2a3d5f1197063fdfe3243eaf9ecb599e77201a06a589b9021845e4fd1d3473c_amd64 |
Timeline
- Feb 26, 2025 CVE Published
- Apr 29, 2026 CVE Updated
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2025:1869 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2335888 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2335901 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1869.json advisory
- https://access.redhat.com/security/cve/CVE-2025-21613 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-21613 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-21613 advisory
- https://github.com/go-git/go-git/security/advisories/GHSA-v725-9546-7q7m advisory
- https://pkg.go.dev/vuln/GO-2025-3368 advisory
- https://access.redhat.com/security/cve/CVE-2025-21614 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-21614 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-21614 advisory
- https://github.com/go-git/go-git/security/advisories/GHSA-r9px-m959-cxf4 advisory
- https://pkg.go.dev/vuln/GO-2025-3367 advisory