CVE-2022-2880

medium
Published 2023-01-23 · Modified 2023-05-12
CVSS v3
CVSS v2
VIR risk
5.5

Description

Moderate: git-lfs security and bug fix update

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-2357.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2113814

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2107388

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2107386

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2107383

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2107374

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2107371

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-2204.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-2780.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:2780

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-0121.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2237778

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2237777

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2237776

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2237773

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2228743

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:0121

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-2167.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2125514

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-0328.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-2784.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2131149

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2124669

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:2784

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-0446.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2132867

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:0446

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-2866.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2161274

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:2866

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-3254.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2268854

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2268046

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2265513

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2132872

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2132868

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:3254

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:0328

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2022-2880

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2022-2880.html

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:0446

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:0121

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:2357

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:2204

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:2167

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:0328

Mitigation details

Source: Red Hat Errata — Red Hat Inc. · View original ↗ · Open-Errata-API

Description golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters Red Hat statement The opportunity to exploit this vulnerability is limited to the Golang runtime. In the case of the OpenShift Container Platform, this would be restricted within each individual container. There are multiple layers of guide rails (Golang’s Garbage Collector; OpenShift’s resource…

Description

golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters

Red Hat statement

The opportunity to exploit this vulnerability is limited to the Golang runtime. In the case of the OpenShift Container Platform, this would be restricted within each individual container. There are multiple layers of guide rails (Golang’s Garbage Collector; OpenShift’s resource constraints imposed at the container and cluster levels) which would require a malicious user to continue submitting attacks for there to be any enduring impact.

CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)

Errata / fixed releases

ProductPackageAdvisoryReleased
OADP-1.1-RHEL-8oadp/oadp-velero-rhel8:1.1.2-16RHSA-2023:11742023-03-09T00:00:00Z
OpenShift Custom Metrics Autoscaler 2custom-metrics-autoscaler-tech-preview/custom-metrics-autoscaler-rhel8:2.8.2-143RHSA-2023:10422023-03-06T00:00:00Z
Openshift Serverless 1 on RHEL 8openshift-serverless-clients-0:1.6.1-1.el8RHSA-2023:07082023-02-09T00:00:00Z
OSSO-1.1-RHEL-8openshift-secondary-scheduler-operator/secondary-scheduler-operator-rhel8:v1.1-26RHSA-2023:05842023-05-18T00:00:00Z
Red Hat Ceph Storage 6.1rhceph/rhceph-6-dashboard-rhel9:6-75RHSA-2023:36422023-06-15T00:00:00Z
Red Hat Developer Toolsgo-toolset-1.18-0:1.18.9-1.el7_9RHSA-2023:04452023-01-25T00:00:00Z
Red Hat Developer Toolsgo-toolset-1.18-golang-0:1.18.9-1.el7_9RHSA-2023:04452023-01-25T00:00:00Z
Red Hat Enterprise Linux 8go-toolset:rhel8-8070020230116141618.ded9a3e2RHSA-2023:04462023-01-25T00:00:00Z
Red Hat Enterprise Linux 8osbuild-composer-0:75-1.el8RHSA-2023:27802023-05-16T00:00:00Z
Red Hat Enterprise Linux 8weldr-client-0:35.9-2.el8RHSA-2023:27802023-05-16T00:00:00Z
Red Hat Enterprise Linux 8grafana-0:7.5.15-4.el8RHSA-2023:27842023-05-16T00:00:00Z
Red Hat Enterprise Linux 8git-lfs-0:3.2.0-2.el8RHSA-2023:28662023-05-16T00:00:00Z
Red Hat Enterprise Linux 8container-tools:4.0-8090020231207142256.d7b6f4b7RHSA-2024:01212024-01-10T00:00:00Z
Red Hat Enterprise Linux 8container-tools:rhel8-8100020240227110532.82888897RHSA-2024:29882024-05-22T00:00:00Z
Red Hat Enterprise Linux 8container-tools:rhel8-8100020240419145834.afee755dRHSA-2024:32542024-05-22T00:00:00Z
Red Hat Enterprise Linux 9golang-0:1.18.9-1.el9_1RHSA-2023:03282023-01-23T00:00:00Z
Red Hat Enterprise Linux 9grafana-0:9.0.9-2.el9RHSA-2023:21672023-05-09T00:00:00Z
Red Hat Enterprise Linux 9osbuild-composer-0:76-2.el9_2RHSA-2023:22042023-05-09T00:00:00Z
Red Hat Enterprise Linux 9weldr-client-0:35.9-1.el9RHSA-2023:22042023-05-09T00:00:00Z
Red Hat Enterprise Linux 9git-lfs-0:3.2.0-1.el9RHSA-2023:23572023-05-09T00:00:00Z
Red Hat Migration Toolkit for Containers 1.7rhmtc/openshift-velero-plugin-rhel8:v1.7.7-3RHSA-2023:06932023-02-09T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/cloud-network-config-controller-rhel8:v4.11.0-202211072116.p0.gfc460d3.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/egress-router-cni-rhel8:v4.11.0-202211072116.p0.gfccaf1d.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/network-tools-rhel8:v4.11.0-202211072116.p0.g4e87286.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/oc-mirror-plugin-rhel8:v4.11.0-202211072116.p0.g3c1c80c.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-agent-installer-api-server-rhel8:v4.11.0-202211072116.p0.g0f52647.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-agent-installer-csr-approver-rhel8:v4.11.0-202211072116.p0.g9a6e300.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-agent-installer-node-agent-rhel8:v4.11.0-202211072116.p0.gb17b06b.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-agent-installer-orchestrator-rhel8:v4.11.0-202211072116.p0.g9a6e300.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-alibaba-cloud-controller-manager-rhel8:v4.11.0-202211072116.p0.g0daf34f.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-alibaba-cloud-csi-driver-container-rhel8:v4.11.0-202211072116.p0.g8dd7ae6.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:v4.11.0-202211072116.p0.gf70a51b.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-alibaba-machine-controllers-rhel8:v4.11.0-202211072116.p0.g4145108.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-apiserver-network-proxy-rhel8:v4.11.0-202211072116.p0.g61e198c.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-aws-cloud-controller-manager-rhel8:v4.11.0-202211072116.p0.gea1a9b2.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-aws-cluster-api-controllers-rhel8:v4.11.0-202211072116.p0.gb3fe15b.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-aws-ebs-csi-driver-rhel8:v4.11.0-202211072116.p0.g550e22c.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-aws-ebs-csi-driver-rhel8-operator:v4.11.0-202211072116.p0.g2c7529e.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-aws-pod-identity-webhook-rhel8:v4.11.0-202211072116.p0.ga085f1c.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-azure-cloud-controller-manager-rhel8:v4.11.0-202211072116.p0.g6bf2e33.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-azure-cloud-node-manager-rhel8:v4.11.0-202211072116.p0.g6bf2e33.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-azure-cluster-api-controllers-rhel8:v4.11.0-202211072116.p0.ga851a35.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-azure-disk-csi-driver-rhel8:v4.11.0-202211072116.p0.g2757f09.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-azure-disk-csi-driver-rhel8-operator:v4.11.0-202211072116.p0.gca54bcb.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-azure-file-csi-driver-operator-rhel8:v4.11.0-202211072116.p0.g4ddaca2.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-azure-file-csi-driver-rhel8:v4.11.0-202211072116.p0.g67c3831.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-baremetal-installer-rhel8:v4.11.0-202211072116.p0.ge1f3399.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-baremetal-machine-controllers:v4.11.0-202211072116.p0.g3cbef7f.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-baremetal-rhel8-operator:v4.11.0-202211072116.p0.g3122fab.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-baremetal-runtimecfg-rhel8:v4.11.0-202211072116.p0.gea6a949.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-cli:v4.11.0-202211072116.p0.g142cb44.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-cli-artifacts:v4.11.0-202211072116.p0.g142cb44.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-cloud-credential-operator:v4.11.0-202211072116.p0.ga36704a.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-cluster-api-rhel8:v4.11.0-202211072116.p0.gf9c215c.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-cluster-authentication-operator:v4.11.0-202211072116.p0.ge2bcbaa.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-cluster-autoscaler:v4.11.0-202211072116.p0.ga25f930.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-cluster-autoscaler-operator:v4.11.0-202211072116.p0.gfcffbcd.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-cluster-baremetal-operator-rhel8:v4.11.0-202211072116.p0.g2c270a5.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-cluster-bootstrap:v4.11.0-202211072116.p0.gf22d1c6.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z
Red Hat OpenShift Container Platform 4.11openshift4/ose-cluster-capi-operator-container-rhel8:v4.11.0-202211072116.p0.g06d77ef.assembly.streamRHSA-2022:85352022-11-24T00:00:00Z

Package state

ProductPackageState
cert-manager Operator for Red Hat OpenShiftcert-manager/cert-manager-operator-rhel9Will not fix
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-controller-rhel9Affected
Node HealthCheck Operatorworkload-availability/node-healthcheck-rhel8-operatorAffected
Node Maintenance Operatorworkload-availability/node-maintenance-rhel8-operatorAffected
OpenShift Developer Tools and ServiceshelmAffected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Affected
OpenShift Developer Tools and ServicesodoAffected
OpenShift Pipelinesopenshift-pipelines-clientWill not fix
Red Hat 3scale API Management Platform 23scale-operator-containerAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/subctl-rhel9Affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Affected
Red Hat AMQ Broker 7amq-broker-rhel8-operator-containerAffected
Red Hat Ansible Automation Platform 2openshift-clientsAffected
Red Hat Ansible Automation Platform 2receptorAffected
Red Hat Application Interconnect 1.0skupper-cliAffected
Red Hat Ceph Storage 3golangOut of support scope
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Affected
Red Hat Enterprise Linux 8container-tools:3.0/buildahWill not fix
Red Hat Enterprise Linux 8container-tools:3.0/podmanAffected
Red Hat Enterprise Linux 8container-tools:3.0/skopeoAffected
Red Hat Enterprise Linux 8grafana-pcpNot affected
Red Hat Enterprise Linux 9buildahWill not fix
Red Hat Enterprise Linux 9conmonNot affected
Red Hat Enterprise Linux 9grafana-pcpNot affected
Red Hat Enterprise Linux 9ignitionWill not fix
Red Hat Enterprise Linux 9podmanWill not fix
Red Hat Enterprise Linux 9skopeoWill not fix
Red Hat OpenShift Container Platform 4cri-oNot affected
Red Hat OpenShift Container Platform 4cri-toolsNot affected
Red Hat OpenShift Container Platform 4openshiftNot affected
Red Hat OpenShift Container Platform 4openshift-golang-builder-containerAffected
Red Hat Openshift Data Foundation 4mcgAffected
Red Hat OpenShift Dev Spacesdevspaces/devspaces-rhel8-operatorWill not fix
Red Hat OpenShift distributed tracing 2rhosdt/jaeger-agent-rhel8Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/gitops-rhel8Affected
Red Hat OpenShift GitOpsopenshift-gitops-kamAffected
Red Hat OpenShift on AWSrosaAffected
Red Hat Quay 3quay/clair-rhel8Affected
Red Hat Storage 3golangOut of support scope
Red Hat Storage 3go-toolset-7-golangOut of support scope
Red Hat Storage 3heketiOut of support scope
Red Hat Web Terminalweb-terminal-exec-containerAffected
Self Node Remediation Operatorworkload-availability/self-node-remediation-rhel8-operatorAffected

Apply commands

bash fix
Apply RHSA-2023:1174 for OADP-1.1-RHEL-8
yum update -y oadp/oadp-velero-rhel8:1
# or:
dnf upgrade -y oadp/oadp-velero-rhel8:1

Affected

VendorProductVersion
redhatMigration Toolkit for VirtualizationAffected
redhatNode HealthCheck OperatorAffected
redhatNode Maintenance OperatorAffected
redhatOpenShift Developer Tools and ServicesAffected
redhatOpenShift Developer Tools and ServicesAffected
redhatOpenShift Developer Tools and ServicesAffected
redhatRed Hat 3scale API Management Platform 2Affected
redhatRed Hat Advanced Cluster Management for Kubernetes 2Affected
redhatRed Hat Advanced Cluster Security 3Affected
redhatRed Hat AMQ Broker 7Affected
redhatRed Hat Ansible Automation Platform 2Affected
redhatRed Hat Ansible Automation Platform 2Affected
redhatRed Hat Application Interconnect 1.0Affected
redhatRed Hat Ceph Storage 5Affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat OpenShift Container Platform 4Not affected
redhatRed Hat OpenShift Container Platform 4Not affected
redhatRed Hat OpenShift Container Platform 4Not affected
redhatRed Hat OpenShift Container Platform 4Affected
redhatRed Hat Openshift Data Foundation 4Affected
redhatRed Hat OpenShift distributed tracing 2Not affected
redhatRed Hat OpenShift GitOpsAffected
redhatRed Hat OpenShift GitOpsAffected
redhatRed Hat OpenShift on AWSAffected
redhatRed Hat Quay 3Affected
redhatRed Hat Web TerminalAffected

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
rockylinux rocky8fixed
suse slesaffected
debian debianbullseyeaffected
debian debianbookwormfixed1.19.2-1
rockylinux rocky9fixed

Package impact

EcosystemPackageVulnerableFixed
golang Gostdlib>=1.19.0-0,<1.19.21.18.7

References

Verify integrity in audit chain (admin only). AS-IS.