Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-64562

Update the dependency "go-git/go-git" to fix CVE-2025-21614 and CVE-2025-21613

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Won't Do
    • Icon: Normal Normal
    • None
    • 4.16.z
    • oc
    • None
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • Low
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      Hello, this is a request to fix the `go-git/go-git` dependency in the oc binary.
      
      The scanner reports the CVE [1] and [2] due to the dependency.
      The fixed version should be 5.13.0 or newer. [3][4]
      
      [1] - https://access.redhat.com/security/cve/cve-2025-21614
      [2] - https://access.redhat.com/security/cve/cve-2025-21613 
      [3] - https://github.com/go-git/go-git/security/advisories/GHSA-r9px-m959-cxf4
      [4] - https://github.com/go-git/go-git/security/advisories/GHSA-v725-9546-7q7m

      Version-Release number of selected component (if applicable):

      OpenShift Container Platform 4.16    

              aos-workloads-staff Workloads Team Bot Account
              rhn-support-vwalek Vladislav Walek
              None
              None
              Ying Zhou Ying Zhou
              None
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: