PT-2024-3567 · Git+11 · Git+11

Filip-Hejsek

·

Published

2024-05-14

·

Updated

2026-05-22

·

CVE-2024-32002

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Git versions prior to 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4
Description The issue allows an attacker to execute arbitrary code when cloning repositories with submodules. This is possible because Git can be fooled into writing files not into the submodule's worktree but into a .git/ directory, enabling the execution of a hook during the clone operation without the user's opportunity to inspect the code. If symbolic link support is disabled in Git, the attack won't work. It is recommended to avoid cloning repositories from untrusted sources.
Recommendations To resolve the issue for each affected version, update Git to version 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, or 2.39.4, or later. As a temporary workaround, consider disabling symbolic link support in Git via git config --global core.symlinks false. For Git for Windows users, update Git by running "git update-git-for-windows".

Exploit

Fix

RCE

Link Following

Path traversal

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

ALSA-2024:4083
ALSA-2024:4084
ALSA-2024_4083
ALSA-2024_4084
ALT-PU-2024-11226
ALT-PU-2024-12519
ALT-PU-2024-17907
ALT-PU-2024-8904
AZL-42040
AZL-43038
BDU:2024-03872
BIT-GIT-2024-32002
CESA-2024_4084
CVE-2024-32002
DLA-3844-1
DLA-3867-1
DSA-5769-1
ELSA-2024-4083
ELSA-2024-4084
GHSA-8H77-4Q3W-GFGV
INFSA-2024_4083
INFSA-2024_4084
MGASA-2024-0204
OESA-2024-1662
OPENSUSE-SU-2024:13968-1
OPENSUSE-SU-2024_1807-1
OPENSUSE-SU-2024_2277-1
RHSA-2024:4083
RHSA-2024:4084
RHSA-2024:4368
RHSA-2024:4579
RHSA-2024:6027
RHSA-2024:6028
RHSA-2024:6610
RHSA-2024_4083
RHSA-2024_4084
RLSA-2024:4083
RLSA-2024:4084
RLSA-2024_4083
RLSA-2024_4084
SUSE-SU-2024:1807-1
SUSE-SU-2024:1807-2
SUSE-SU-2024:1854-1
SUSE-SU-2024:2277-1
SUSE-SU-2024_1807-1
SUSE-SU-2024_1854-1
SUSE-SU-2024_2277-1
SUSE-SU-2025:0197-1
SUSE-SU-2025:20049-1
SUSE-SU-2025_0197-1
USN-6793-1
USN-6793-2
USN-7023-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Git
Linuxmint
Apple Macos
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu