StackRadar

CVE-2023-49569

Critical

Advisory

Published 10 Jan 2024In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.015
73rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
82
of 17,781 indexed, latest versions
Container images
74
deployed by those charts
Fix available
1 of 2
affected packages

Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

Carried by container images the latest versions of 82 of 17,781 indexed charts deploy, on 74 images.

Affected packageAffected versionsFixed inImages
github.com/go-git/go-git/v5golangv5.0.0, v5.1.0, v5.2.0, v5.3.0+7 more5.11.061
gopkg.in/src-d/go-git.v4golangv4.10.0, v4.13.1no fix listed16
OSV records
GHSA-449p-3h89-pw88
Also known as
GO-2024-2456

Charts affected

82 by stars
ChartLatestAffected imagesRadar Score
u4a-componentkubebb0.2.101 of 8See more

u4a-component kubebb 0.2.10

1 of the 8 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
kubebb/oidc-server:v0.2.02b5894ef1e2f
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

13,819
grafanakubeblocksVerified publisher6.59.41 of 1See more

grafana kubeblocks 6.59.4

1 of the 1 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
grafana/grafana:10.1.11b9ca4bbc4a2
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

3,561
kubeclaritykubeclarity2.23.31 of 5See more

kubeclarity kubeclarity 2.23.3

1 of the 5 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
ghcr.io/openclarity/grype-server:v0.6.079412399f301
github.com/go-git/go-git/v5@v5.8.1
5.11.0

Open the chart page →

5,496
harborkubesphereVerified publisher1.9.31 of 11See more

harbor kubesphere 1.9.3

1 of the 11 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

17,798
deepflowkubesphere-stable6.2.6061 of 8See more

deepflow kubesphere-stable 6.2.606

1 of the 8 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
grafana/grafana:9.5.239c849cebccc
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

18,316
trivy-serverlemontechVerified publisher0.1.01 of 1See more

trivy-server lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
aquasec/trivy:0.32.0973d0df16189
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

4,271
devspace-cloudloftVerified publisher0.3.31 of 8See more

devspace-cloud loft 0.3.3

1 of the 8 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
devspacecloud/manager:0.3.349c397413f7b
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

9,880
kubeaddons-catalogmesosphere0.1.161 of 2See more

kubeaddons-catalog mesosphere 0.1.16

1 of the 2 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
github.com/go-git/go-git/v5@v5.1.0
5.11.0

Open the chart page →

12,010
dexmesosphere-stable2.14.11 of 5See more

dex mesosphere-stable 2.14.1

1 of the 5 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
mesosphere/dex:v2.37.0-d2iq.1b093d78a21ed
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

19,214
kommandermesosphere-stable0.39.22 of 29See more

kommander mesosphere-stable 0.39.2

2 of the 29 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
mesosphere/kommander-federation-utility-apiserver:v0.21.2f9b769c65e24
github.com/go-git/go-git/v5@v5.2.0
gopkg.in/src-d/go-git.v4@v4.13.1
5.11.0
no fix listed
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
github.com/go-git/go-git/v5@v5.1.0
5.11.0

Open the chart page →

68,284
giteanovum-rgi-charts2.1.31 of 3See more

gitea novum-rgi-charts 2.1.3

1 of the 3 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
gitea/gitea:1.13.0d5ab14cd29af
github.com/go-git/go-git/v5@v5.1.0
5.11.0

Open the chart page →

4,861
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

8,540
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/go-git/go-git/v5@v5.3.0
5.11.0

Open the chart page →

8,599
npre-essentialsphntom0.1.601 of 22See more

npre-essentials phntom 0.1.60

1 of the 22 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
quay.io/groundcover/grafana:9.3.18c65b333a3d3
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

26,840
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

9,606
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

29,227
argocdromholdings1.8.11 of 3See more

argocd romholdings 1.8.1

1 of the 3 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

10,466
devtron-enterpriseromholdings48.0.03 of 28See more

devtron-enterprise romholdings 48.0.0

3 of the 28 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
quay.io/devtron/dex:v2.30.22e4c14d1b444
github.com/go-git/go-git/v5@v5.2.0
5.11.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/go-git/go-git/v5@v5.7.0
5.11.0
quay.io/devtron/kubectl:latest2ad610626658
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

68,240
devtron-in-clustercdromholdings0.10.21 of 2See more

devtron-in-clustercd romholdings 0.10.2

1 of the 2 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/go-git/go-git/v5@v5.6.1
5.11.0

Open the chart page →

5,039
devtron-operatorromholdings0.23.32 of 11See more

devtron-operator romholdings 0.23.3

2 of the 11 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
quay.io/devtron/dex:v2.30.22e4c14d1b444
github.com/go-git/go-git/v5@v5.2.0
5.11.0
quay.io/devtron/kubectl:latest2ad610626658
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

32,902
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
github.com/go-git/go-git/v5@v5.8.1
5.11.0

Open the chart page →

2,314
metrics-generatorsikalabs0.2.01 of 1See more

metrics-generator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
sikalabs/slu:v0.34.0fdc0c6711add
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

2,381
harborsoftonic1.13.01 of 8See more

harbor softonic 1.13.0

1 of the 8 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/go-git/go-git/v5@v5.7.0
5.11.0

Open the chart page →

7,672
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/go-git/go-git/v5@v5.7.0
5.11.0

Open the chart page →

2,505
whitelisterstakaterVerified publisher0.0.161 of 1See more

whitelister stakater 0.0.16

1 of the 1 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
stakater/whitelister:v0.0.1639107924063e
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

2,564
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

6,671
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

10,134
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

10,902
agentssynapse0.1.302 of 9See more

agents synapse 0.1.30

2 of the 9 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
github.com/go-git/go-git/v5@v5.5.2
5.11.0
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
github.com/go-git/go-git/v5@v5.5.2
5.11.0

Open the chart page →

7,244
cctpsynapse0.3.01 of 4See more

cctp synapse 0.3.0

1 of the 4 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
github.com/go-git/go-git/v5@v5.5.2
5.11.0

Open the chart page →

1,815
promexportersynapse0.1.11 of 1See more

promexporter synapse 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
github.com/go-git/go-git/v5@v5.5.2
5.11.0

Open the chart page →

1,704
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2023-49569.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

4,086

Container images carrying it

74 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
sikalabs/slu:v0.72.07bd267f30247
github.com/go-git/go-git/v5@v5.8.1
5.11.0
1
sikalabs/slu:v0.34.0fdc0c6711add
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
stakater/whitelister:v0.0.1639107924063e
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1
stakater/workshop-operator:v0.0.3897bf456cc97c
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/go-git/go-git/v5@v5.7.0
5.11.0
1
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
github.com/go-git/go-git/v5@v5.7.0
5.11.0
1
ghcr.io/dexidp/dex:v2.35.313964b29d63e
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
github.com/go-git/go-git/v5@v5.2.0
5.11.0
1
ghcr.io/openclarity/grype-server:v0.6.079412399f301
github.com/go-git/go-git/v5@v5.8.1
5.11.0
1
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
github.com/go-git/go-git/v5@v5.5.2
5.11.0
1
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
github.com/go-git/go-git/v5@v5.5.2
5.11.0
1
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
github.com/go-git/go-git/v5@v5.5.2
5.11.0
1
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
github.com/go-git/go-git/v5@v5.5.2
5.11.0
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
github.com/go-git/go-git/v5@v5.7.0
5.11.0
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
github.com/go-git/go-git/v5@v5.3.0
5.11.0
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
github.com/go-git/go-git/v5@v5.3.0
gopkg.in/src-d/go-git.v4@v4.13.1
5.11.0
no fix listed
1
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
github.com/go-git/go-git/v5@v5.6.1
5.11.0
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/go-git/go-git/v5@v5.3.0
5.11.0
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.