PT-2024-3747 · Git+10 · Git+10

Filip-Hejsek

·

Published

2024-05-14

·

Updated

2026-06-11

·

CVE-2024-32004

CVSS v3.1

8.1

High

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Git versions prior to 2.45.1 Git versions prior to 2.44.1 Git versions prior to 2.43.4 Git versions prior to 2.42.2 Git versions prior to 2.41.1 Git versions prior to 2.40.2 Git versions prior to 2.39.4
Description: The issue exists due to a problem with process management in the Git revision control system. An attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. As a workaround, avoid cloning repositories from untrusted sources.
Recommendations: For versions prior to 2.45.1, update to version 2.45.1 or later. For versions prior to 2.44.1, update to version 2.44.1 or later. For versions prior to 2.43.4, update to version 2.43.4 or later. For versions prior to 2.42.2, update to version 2.42.2 or later. For versions prior to 2.41.1, update to version 2.41.1 or later. For versions prior to 2.40.2, update to version 2.40.2 or later. For versions prior to 2.39.4, update to version 2.39.4 or later. As a temporary workaround, consider avoiding cloning repositories from untrusted sources until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:4083
ALSA-2024:4084
ALSA-2024_4083
ALSA-2024_4084
ALT-PU-2024-12519
ALT-PU-2024-17907
ALT-PU-2024-8904
AZL-42022
AZL-43041
BDU:2024-04093
BIT-GIT-2024-32004
CESA-2024_4084
CVE-2024-32004
DLA-3844-1
DLA-3867-1
DSA-5769-1
GHSA-XFC6-VWR8-R389
INFSA-2024_4083
INFSA-2024_4084
MGASA-2024-0204
OESA-2024-1662
OPENSUSE-SU-2024:13968-1
OPENSUSE-SU-2024_1807-1
OPENSUSE-SU-2024_2277-1
RHSA-2024:4083
RHSA-2024:4084
RHSA-2024:4368
RHSA-2024:4579
RHSA-2024:6027
RHSA-2024:6028
RHSA-2024:6610
RHSA-2024:7701
RHSA-2024_4083
RHSA-2024_4084
RLSA-2024:4083
RLSA-2024:4084
SUSE-SU-2024:1807-1
SUSE-SU-2024:1807-2
SUSE-SU-2024:1854-1
SUSE-SU-2024:2277-1
SUSE-SU-2025:0197-1
SUSE-SU-2025:20049-1
SUSE-SU-2025_0197-1
USN-6793-1
USN-7023-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Git
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu