AZL-39595
Dashboard / Vulnerabilities / AZL-39595
Summary: CVE-2023-49568 affecting package cri-o for versions less than 1.22.3-12
Details: A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Applications using only the in-memory filesystem supported by go-git are not affected by this vulnerability. This is a go-git implementation issue and does not affect the upstream git cli.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-49568
Affected packages
Package
Name: cri-o
Purl: pkg:rpm/azure-linux/cri-o
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -1.22.3-12
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
