PT-2024-24601 · Unknown · Git Credential Manager

Jim-Minter

·

Published

2024-04-19

·

Updated

2024-04-19

·

CVE-2024-32478

CVSS v3.1

6.9

Medium

VectorAV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Git Credential Manager (GCM) versions prior to 2.5.0
Description The issue arises from the Debian package of Git Credential Manager (GCM) not setting root ownership on installed files prior to version 2.5.0. This allows a user on a multi-user system to replace the binary and gain privileges of other users.
Recommendations For versions prior to 2.5.0, update to version 2.5.0 to resolve the issue. As a temporary workaround, consider setting root ownership on installed files manually until the update can be applied.

Exploit

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2024-32478
GHSA-3C3G-H9RX-F7VQ

Affected Products

Git Credential Manager