The vendor explicitly identifies these products as affected by this CVE.
- emacs-git as a component of Red Hat Enterprise Linux 6
- emacs-git-el as a component of Red Hat Enterprise Linux 6
- git as a component of Red Hat Enterprise Linux 6
- git-all as a component of Red Hat Enterprise Linux 6
- git-cvs as a component of Red Hat Enterprise Linux 6
- git-daemon as a component of Red Hat Enterprise Linux 6
- git-email as a component of Red Hat Enterprise Linux 6
- git-gui as a component of Red Hat Enterprise Linux 6
- git-svn as a component of Red Hat Enterprise Linux 6
- git.src as a component of Red Hat Enterprise Linux 6
- gitk as a component of Red Hat Enterprise Linux 6
- gitweb as a component of Red Hat Enterprise Linux 6
- Summary
- A bundled uri handling flaw was found in Git. When cloning a repository, Git knows to optionally fetch a bundle advertised by the remote server, which allows the server side to offload parts of the clone to a CDN. The Git client does not perform sufficient validation of the advertised bundles, which allows the remote side to perform protocol injection.
- Remediation
- The RHEL-8 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References). Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.
