VDB

RHSA-2025%3A1870

RHSA-2025%3A1870 PUBLISHED CVSS 8.100000381469727 HIGH

An argument injection vulnerability was found in go-git. This flaw allows an attacker to set arbitrary values to git-upload-pack flags, leading to command or code execution, exposure of sensitive data, or other unintended behavior. This is only possible in configurations where the file transport protocol is being used.

Risk Scores

CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red Hatrhosp-rhel9/osp-director-downloader@sha256:034891a629861fa1e3947466141787d5211b97e69f0d2b7a74516bfeb9f191d7_amd64 as a component of Red Hat OpenStack Platform 17.1rhosp-rhel9/osp-director-downloader@sha256:034891a629861fa1e3947466141787d5211b97e69f0d2b7a74516bfeb9f191d7_amd64
Red Hatrhosp-rhel9/osp-director-agent@sha256:a72382bacac1d99ee3c7391cb76b5930e9424b6e8fa3deed8dda03b054495f84_amd64 as a component of Red Hat OpenStack Platform 17.1rhosp-rhel9/osp-director-agent@sha256:a72382bacac1d99ee3c7391cb76b5930e9424b6e8fa3deed8dda03b054495f84_amd64
Red Hatrhosp-rhel9/osp-director-operator-bundle@sha256:a5a31f5e21b190a208348d5d1e3c8f791ffdf7ec7c1d65f80bd796cf4522d014_amd64 as a component of Red Hat OpenStack Platform 17.1rhosp-rhel9/osp-director-operator-bundle@sha256:a5a31f5e21b190a208348d5d1e3c8f791ffdf7ec7c1d65f80bd796cf4522d014_amd64
Red Hatrhosp-rhel9/osp-director-operator@sha256:93a5bf00b2caf1f65558275f8fa18a36286134010b72d16e4b8ac72ed1e460e5_amd64 as a component of Red Hat OpenStack Platform 17.1rhosp-rhel9/osp-director-operator@sha256:93a5bf00b2caf1f65558275f8fa18a36286134010b72d16e4b8ac72ed1e460e5_amd64

Timeline

  • Feb 26, 2025 CVE Published
  • Apr 29, 2026 CVE Updated
  • Apr 29, 2026 Distribution Patch
  • Apr 29, 2026 Distribution Patch
  • Apr 29, 2026 Security Advisory
  • Apr 29, 2026 Security Advisory
  • Apr 29, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›