The vendor explicitly identifies these products as affected by this CVE.
- ansible-automation-platform-26/controller-rhel9 as a component of Red Hat Ansible Automation Platform 2
- ansible-automation-platform-27/controller-rhel9 as a component of Red Hat Ansible Automation Platform 2
- rhoai/odh-kserve-storage-initializer-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- python-dulwich.src as a component of Red Hat OpenShift Container Platform 4
- Summary
- A flaw was found in Dulwich, a pure-Python implementation of Git file formats and protocols. An attacker can exploit this vulnerability by crafting malicious file paths within an untrusted Git branch. When a victim merges this branch, the ProcessMergeDriver component incorrectly substitutes the attacker-controlled file path into a command, leading to arbitrary code execution. This allows the attacker to run unauthorized commands on the victim's system.
- Remediation
- Affected
