Arbitrary Code Execution Vulnerability in Git Repositories
CVE-2024-32004
Summary
A significant vulnerability has been identified in Git, which may allow an attacker to execute arbitrary code during the cloning process of a repository. This vulnerability is present in Git versions prior to 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. When a local repository is specially crafted, unsuspecting users who clone this repository may inadvertently execute malicious code, posing serious security risks. To mitigate potential threats associated with this vulnerability, it is advised to avoid cloning repositories from untrusted sources until the affected versions are updated to the patched releases.
Affected Version(s)
git = 2.45.0 = 2.45.0
git = 2.44.0 = 2.44.0
git >= 2.43.0, < 2.43.4 < 2.43.0, 2.43.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved