VDB
RHSA-2025%3A1870
RHSA-2025%3A1870
PUBLISHED
CVSS 8.100000381469727 HIGH
An argument injection vulnerability was found in go-git. This flaw allows an attacker to set arbitrary values to git-upload-pack flags, leading to command or code execution, exposure of sensitive data, or other unintended behavior. This is only possible in configurations where the file transport protocol is being used.
Risk Scores
CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhosp-rhel9/osp-director-downloader@sha256:034891a629861fa1e3947466141787d5211b97e69f0d2b7a74516bfeb9f191d7_amd64 as a component of Red Hat OpenStack Platform 17.1 | rhosp-rhel9/osp-director-downloader@sha256:034891a629861fa1e3947466141787d5211b97e69f0d2b7a74516bfeb9f191d7_amd64 |
| Red Hat | rhosp-rhel9/osp-director-agent@sha256:a72382bacac1d99ee3c7391cb76b5930e9424b6e8fa3deed8dda03b054495f84_amd64 as a component of Red Hat OpenStack Platform 17.1 | rhosp-rhel9/osp-director-agent@sha256:a72382bacac1d99ee3c7391cb76b5930e9424b6e8fa3deed8dda03b054495f84_amd64 |
| Red Hat | rhosp-rhel9/osp-director-operator-bundle@sha256:a5a31f5e21b190a208348d5d1e3c8f791ffdf7ec7c1d65f80bd796cf4522d014_amd64 as a component of Red Hat OpenStack Platform 17.1 | rhosp-rhel9/osp-director-operator-bundle@sha256:a5a31f5e21b190a208348d5d1e3c8f791ffdf7ec7c1d65f80bd796cf4522d014_amd64 |
| Red Hat | rhosp-rhel9/osp-director-operator@sha256:93a5bf00b2caf1f65558275f8fa18a36286134010b72d16e4b8ac72ed1e460e5_amd64 as a component of Red Hat OpenStack Platform 17.1 | rhosp-rhel9/osp-director-operator@sha256:93a5bf00b2caf1f65558275f8fa18a36286134010b72d16e4b8ac72ed1e460e5_amd64 |
Timeline
- Feb 26, 2025 CVE Published
- Apr 29, 2026 CVE Updated
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2025:1870 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2335888 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2335901 issue
- https://issues.redhat.com/browse/OSPRH-12350 advisory
- https://issues.redhat.com/browse/OSPRH-14161 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1870.json advisory
- https://access.redhat.com/security/cve/CVE-2025-21613 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-21613 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-21613 advisory
- https://github.com/go-git/go-git/security/advisories/GHSA-v725-9546-7q7m advisory
- https://pkg.go.dev/vuln/GO-2025-3368 advisory
- https://access.redhat.com/security/cve/CVE-2025-21614 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-21614 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-21614 advisory
- https://github.com/go-git/go-git/security/advisories/GHSA-r9px-m959-cxf4 advisory
- https://pkg.go.dev/vuln/GO-2025-3367 advisory