Junglewise Threat Intelligence

CVE-2023-49569: GO-2024-2456 - Path traversal and RCE in github.com/go-git/go-git/v5 and gopkg.in/src-d/go-git.v4

CVE-2023-49569 · Severity: low · CVSS 3.1 · Published 2024-01-23

Technologies: github.com/go-git/go-git/v5 (Go), gopkg.in/src-d/go-git.v4 (Go). Vendors: Go.

Executive brief

Path traversal and RCE in github.com/go-git/go-git/v5 and gopkg.in/src-d/go-git.v4

Affected products

  • Go github.com/go-git/go-git/v5
  • Go gopkg.in/src-d/go-git.v4

Related threats