CVE-2025-48385

Red Hat Security Advisory: updated web-terminal/tooling container image

Description

A bundled uri handling flaw was found in Git. When cloning a repository, Git knows to optionally fetch a bundle advertised by the remote server, which allows the server side to offload parts of the clone to a CDN. The Git client does not perform sufficient validation of the advertised bundles, which allows the remote side to perform protocol injection.

Metrics

Severity
high
no public PoC known
8.6
Source: nvd-v4
58.5 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
0.9 %
Low — model estimates < 1% exploitation likelihood.
Published
2025-09-15 15:14 UTC
CWE-88, CWE-73

Weakness classes (CWE)

  • CWE-88Base

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

    The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

    cwe.mitre.org →
  • CWE-73Base

    External Control of File Name or Path

    The product allows user input to control or influence paths or file names that are used in filesystem operations.

    cwe.mitre.org →

Affected operating systems

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux6.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • bitnami

    git

  • bitnami

    java-min1.9.0

  • bitnami

    sqlite

  • go

    golang.org/x/net

  • go

    stdlib1.22.0-0

  • libarchive

    libarchive3.8.0

  • Oracle

    Fusion Middleware12.2.1.4.0

  • Oracle

    Fusion Middleware14.1.1.0.0

  • Oracle

    Fusion Middleware14.1.2.0.0

  • Oracle

    Fusion Middleware14.1.2.1.0

  • Oracle

    Fusion Middleware15.1.1.0.0

  • Oracle

    Fusion Middleware8.5.7

  • Oracle

    Fusion Middleware8.5.8

  • redhat

    openshift_container_platform

References & sources

Linked CVEs

IDCVE-2025-48385