Arbitrary Code Execution Vulnerability in Git Repositories
CVE-2024-32004

8.2HIGH

Key Information:

Vendor
Git
Status
Vendor
CVE Published:
14 May 2024

Summary

A significant vulnerability has been identified in Git, which may allow an attacker to execute arbitrary code during the cloning process of a repository. This vulnerability is present in Git versions prior to 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. When a local repository is specially crafted, unsuspecting users who clone this repository may inadvertently execute malicious code, posing serious security risks. To mitigate potential threats associated with this vulnerability, it is advised to avoid cloning repositories from untrusted sources until the affected versions are updated to the patched releases.

Affected Version(s)

git = 2.45.0 = 2.45.0

git = 2.44.0 = 2.44.0

git >= 2.43.0, < 2.43.4 < 2.43.0, 2.43.4

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.