RHSA-2025:1869HighCVSS 8.1
Red Hat Security Advisory: Red Hat OpenStack Platform 16.2 (osp-director-operator) security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-21613 — go-git: argument injection via the URL field CVE-2025-21614 — go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies
🎯 Affected products5
- Red Hat OpenStack Platform 16.2
- rhosp-rhel8/osp-director-agent@sha256:2732885be77c420c09d4b193256f98f791fbaf68b0df53ce74a075312d5909be_amd64 as a component of Red Hat OpenStack Platform 16.2
- rhosp-rhel8/osp-director-downloader@sha256:d2a3d5f1197063fdfe3243eaf9ecb599e77201a06a589b9021845e4fd1d3473c_amd64 as a component of Red Hat OpenStack Platform 16.2
- rhosp-rhel8/osp-director-operator-bundle@sha256:65acbffc986354da1ce64aff2f02fb32b91a307852317b50516adc19f2c75c6e_amd64 as a component of Red Hat OpenStack Platform 16.2
- rhosp-rhel8/osp-director-operator@sha256:f688739a10ab007f7a8a0de75327d56a67a9da1182d9a06130d75e0b57617da9_amd64 as a component of Red Hat OpenStack Platform 16.2
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: In cases where it is not possible to update to the latest version of go-git, it is recommended to enforce validation rules for values passed in the URL field.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2025:1869
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2335888
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2335901
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1869.json