The vendor explicitly identifies these products as affected by this CVE.
- openshift-golang-builder-container as a component of Red Hat OpenShift Virtualization 4
- golang-bin as a component of Red Hat Storage 3
- golang-docs as a component of Red Hat Storage 3
- golang-misc as a component of Red Hat Storage 3
- golang-src as a component of Red Hat Storage 3
- golang-tests as a component of Red Hat Storage 3
- golang.src as a component of Red Hat Storage 3
- Summary
- A flaw was found in the Golang package cmd/go. This issue permits the fallback to insecure "git://" if trying to fetch a .git module that has no "https://" or "git+ssh://" available.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
