CVE-2023-49569
CriticalAdvisory
Published 10 Jan 2024In the index since 6 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.015
- 73rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 82
- of 17,781 indexed, latest versions
- Container images
- 74
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
Carried by container images the latest versions of 82 of 17,781 indexed charts deploy, on 74 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v5.0.0, v5.1.0, v5.2.0, v5.3.0+7 more | 5.11.0 | 61 |
| gopkg.in/ | v4.10.0, v4.13.1 | no fix listed | 16 |
- OSV records
- GHSA-449p-3h89-pw88
- Also known as
- GO-2024-2456
Charts affected
82 by stars
Container images carrying it
74 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | 2e4c14d1b444 | github.com/ | 5.11.0 | 6 |
| quay.io/ | 2ad610626658 | github.com/ | 5.11.0 | 6 |
| argoproj/ | 830e86cacefd | gopkg.in/ | no fix listed | 3 |
| quay.io/ | 98580969b333 | github.com/ | 5.11.0 | 3 |
| quay.io/ | eec0305b594c | github.com/ | 5.11.0 | 3 |
| datawire/ | 8588eafe6862 | gopkg.in/ | no fix listed | 2 |
| grafana/ | 057896e23443 | github.com/ | 5.11.0 | 2 |
| mesosphere/ | 073db43d0b8b | github.com/ | 5.11.0 | 2 |
| streamnative/ | 0e6d7aa3ef32 | github.com/ | 5.11.0 | 2 |
| ghcr.io/ | 5e88f2205de1 | github.com/ | 5.11.0 | 2 |
| quay.io/ | 8c65b333a3d3 | github.com/ | 5.11.0 | 2 |
| aquasec/ | 7ea4aa3d2eb6 | github.com/ | 5.11.0 | 1 |
| aquasec/ | 944a04445179 | github.com/ | 5.11.0 | 1 |
| aquasec/ | 973d0df16189 | github.com/ | 5.11.0 | 1 |
| chaosnative/ | e7bcff4a20c0 | github.com/ | 5.11.0 | 1 |
| charmcli/ | 39523c1a6ba8 | github.com/ | 5.11.0 | 1 |
| datappeal/ | e38c085a3567 | gopkg.in/ | no fix listed | 1 |
| datawire/ | 07f8fe4f4f8e | gopkg.in/ | no fix listed | 1 |
| datawire/ | 2beb65062c8b | gopkg.in/ | no fix listed | 1 |
| devopstales/ | 75136aa7a26e | github.com/ | 5.11.0 | 1 |
| devspacecloud/ | 49c397413f7b | gopkg.in/ | no fix listed | 1 |
| epamedp/ | 96028c86f0dd | github.com/ | 5.11.0 | 1 |
| epamedp/ | 616c678ba3e7 | gopkg.in/ | no fix listed | 1 |
| epamedp/ | b71fb39e0c9e | github.com/ | 5.11.0 | 1 |
| epamedp/ | d33e938b6d59 | github.com/ | 5.11.0 | 1 |
| flanksource/ | 1dacc3195bf9 | github.com/ | 5.11.0 | 1 |
| fluxcd/ | 31a8c79a6803 | github.com/ | 5.11.0 | 1 |
| gitea/ | 85416d6f65fe | github.com/ | 5.11.0 | 1 |
| gitea/ | d5ab14cd29af | github.com/ | 5.11.0 | 1 |
| goharbor/ | b9522c3f5056 | github.com/ | 5.11.0 | 1 |
| goharbor/ | dc5b882a7db4 | github.com/ | 5.11.0 | 1 |
| grafana/ | 0679e877ba20 | github.com/ | 5.11.0 | 1 |
| grafana/ | 1a359d92f40e | github.com/ | 5.11.0 | 1 |
| grafana/ | 1b9ca4bbc4a2 | github.com/ | 5.11.0 | 1 |
| grafana/ | 39c849cebccc | github.com/ | 5.11.0 | 1 |
| grafana/ | 76dcf36e7d2a | github.com/ | 5.11.0 | 1 |
| grafana/ | 9746858c20e6 | github.com/ | 5.11.0 | 1 |
| hashicorp/ | 97d521a27498 | github.com/ gopkg.in/ | 5.11.0 no fix listed | 1 |
| inseefrlab/ | 31f04ca7436b | gopkg.in/ | no fix listed | 1 |
| invisibl/ | 1a970f84178b | github.com/ | 5.11.0 | 1 |
| iotaledger/ | b02a8f77474f | gopkg.in/ | no fix listed | 1 |
| kubebb/ | 2b5894ef1e2f | github.com/ | 5.11.0 | 1 |
| layer5/ | 25a4cc38abcd | github.com/ | 5.11.0 | 1 |
| layer5/ | ec898e5786c6 | github.com/ | 5.11.0 | 1 |
| layer5/ | 797fa7a03570 | github.com/ | 5.11.0 | 1 |
| mesosphere/ | b093d78a21ed | github.com/ | 5.11.0 | 1 |
| mesosphere/ | f9b769c65e24 | github.com/ gopkg.in/ | 5.11.0 no fix listed | 1 |
| ntakashi/ | 4171ec641120 | github.com/ | 5.11.0 | 1 |
| owncloud/ | d2efcae92c84 | github.com/ | 5.11.0 | 1 |
| portainer/ | 3e61aaee1341 | github.com/ | 5.11.0 | 1 |