PT-2024-3747 · Git+10 · Git+10
Filip-Hejsek
·
Published
2024-05-14
·
Updated
2026-06-11
·
CVE-2024-32004
CVSS v3.1
8.1
High
| Vector | AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Git versions prior to 2.45.1
Git versions prior to 2.44.1
Git versions prior to 2.43.4
Git versions prior to 2.42.2
Git versions prior to 2.41.1
Git versions prior to 2.40.2
Git versions prior to 2.39.4
Description:
The issue exists due to a problem with process management in the Git revision control system. An attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. As a workaround, avoid cloning repositories from untrusted sources.
Recommendations:
For versions prior to 2.45.1, update to version 2.45.1 or later.
For versions prior to 2.44.1, update to version 2.44.1 or later.
For versions prior to 2.43.4, update to version 2.43.4 or later.
For versions prior to 2.42.2, update to version 2.42.2 or later.
For versions prior to 2.41.1, update to version 2.41.1 or later.
For versions prior to 2.40.2, update to version 2.40.2 or later.
For versions prior to 2.39.4, update to version 2.39.4 or later.
As a temporary workaround, consider avoiding cloning repositories from untrusted sources until the issue is resolved.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Git
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu