go-git
cpe:2.3:a:go-git_project:go-git:*:*:*:*:go:*:*
- >= 4, < 5.13.0
An argument injection vulnerability has been identified in go-git, a Git implementation library written in Go, affecting versions 4.0.0 prior to 5.13.0. The vulnerability arises when the file transport protocol is used, as this is the only protocol that interacts with Git binaries. Exploitation could allow an attacker to inject arbitrary values into git-upload-pack flags.
Exploitation could lead to unauthorized modification of git-upload-pack flags, potentially allowing for manipulation of Git operations or behavior.
Users are advised to upgrade to go-git version 5.13.0. If an immediate upgrade is not possible, it is recommended to implement strict validation rules for values in the URL field.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.