CVE-2025-48385
Red Hat Security Advisory: updated web-terminal/tooling container image
Description
A bundled uri handling flaw was found in Git. When cloning a repository, Git knows to optionally fetch a bundle advertised by the remote server, which allows the server side to offload parts of the clone to a CDN. The Git client does not perform sufficient validation of the advertised bundles, which allows the remote side to perform protocol injection.
Metrics
Weakness classes (CWE)
CWE-88Base
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
cwe.mitre.org →CWE-73Base
External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
cwe.mitre.org →
Affected operating systems
linux
debian / debian_linux11.0
linux
redhat / enterprise_linux10.0
linux
redhat / enterprise_linux6.0
linux
redhat / enterprise_linux7.0
linux
redhat / enterprise_linux8.0
linux
redhat / enterprise_linux9.0
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
bitnami
git
bitnami
java-min1.9.0
bitnami
sqlite
go
golang.org/x/net
go
stdlib1.22.0-0
libarchive
libarchive3.8.0
Oracle
Fusion Middleware12.2.1.4.0
Oracle
Fusion Middleware14.1.1.0.0
Oracle
Fusion Middleware14.1.2.0.0
Oracle
Fusion Middleware14.1.2.1.0
Oracle
Fusion Middleware15.1.1.0.0
Oracle
Fusion Middleware8.5.7
Oracle
Fusion Middleware8.5.8
redhat
openshift_container_platform
References & sources
- https://access.redhat.com/errata/RHSA-2025:14557vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15099vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15100vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15101vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15102vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15103vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15104vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15105vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15106vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15107vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15709vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15827vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15828vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:16524vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:17181vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:18219vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:21885vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-8941vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2388220issue-trackingx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:10630vendor-advisoryx_refsource_REDHAT
Linked CVEs
- CVE-2025-8941
A flaw was found in linux-pam.
highCVSSv3 7.8 - CVE-2025-7425
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management.
highCVSSv3 7.8 - CVE-2025-6965
A memory corruption flaw was found in SQLite.
high - CVE-2025-6020
A flaw was found in linux-pam.
highCVSSv3 7.8 - CVE-2025-5914
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function.
highCVSSv3 7.8 - CVE-2025-49796
A vulnerability was found in libxml2.
criticalCVSSv3 9.1 - CVE-2025-49794
A use-after-free vulnerability was found in libxml2.
criticalCVSSv3 9.1 - CVE-2025-48384Actively exploited
A line-end handling flaw was found in Git.
criticalCVSSv3 8.1 - CVE-2023-45288
A vulnerability was discovered with the implementation of the HTTP/2 protocol in the Go programming language.
—