[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2024-2458 --- amazon-ssm-agent

ID: oval:org.secpod.oval:def:1702129Date: (C)2024-02-28   (M)2024-02-28
Class: PATCHFamily: unix




A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, remote code execution could be achieved.Applications are only affected if they are using the ChrootOS https://pkg.go.dev/github.com/go-git/go-billy/v5/osfs#ChrootOS , which is the default when using "Plain" versions of Open and Clone funcs . Applications using BoundOS https://pkg.go.dev/github.com/go-git/go-billy/v5/osfs#BoundOS or in-memory filesystems are not affected by this issue.This is a go-git implementation issue and does not affect the upstream git cli

Platform:
Amazon Linux 2
Product:
amazon-ssm-agent
Reference:
ALAS2-2024-2458
CVE-2023-49569
CVE    1
CVE-2023-49569
CPE    1
cpe:/o:amazon:linux:2

© SecPod Technologies