PT-2025-2920 · Unknown+11 · Git Credential Manager+11

Felix Wilhelm

·

Published

2025-01-14

·

Updated

2026-01-15

·

CVE-2024-52006

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Git versions prior to v2.48.1 Git versions prior to v2.47.2 Git versions prior to v2.46.3 Git versions prior to v2.45.3 Git versions prior to v2.44.3 Git versions prior to v2.43.6 Git versions prior to v2.42.4 Git versions prior to v2.41.3 Git versions prior to v2.40.4
Description The issue is related to the Git credential protocol, which is text-based and consists of key-value pairs. A mismatch in newline treatment between Git and the Git Credential Manager (GCM) allows an attacker to craft a malicious remote URL. This can lead to the capture of credentials for another Git remote. The attack is heightened when cloning from repositories with submodules using the --recursive clone option.
Recommendations For versions prior to v2.48.1, upgrade to v2.48.1 or later. For versions prior to v2.47.2, upgrade to v2.47.2 or later. For versions prior to v2.46.3, upgrade to v2.46.3 or later. For versions prior to v2.45.3, upgrade to v2.45.3 or later. For versions prior to v2.44.3, upgrade to v2.44.3 or later. For versions prior to v2.43.6, upgrade to v2.43.6 or later. For versions prior to v2.42.4, upgrade to v2.42.4 or later. For versions prior to v2.41.3, upgrade to v2.41.3 or later. For versions prior to v2.40.4, upgrade to v2.40.4 or later. As a temporary workaround, consider avoiding cloning from untrusted URLs, especially recursive clones.

Exploit

Fix

Information Disclosure

Improper Encoding or Escaping of Output

Related Identifiers

ALSA-2025:11462
ALSA-2025:11533
ALSA-2025:11534
ALSA-2025_11462
ALSA-2025_11534
ALT-PU-2025-10893
ALT-PU-2025-1641
ALT-PU-2025-1942
ALT-PU-2025-2059
AZL-55652
AZL-55667
BDU:2025-01177
BIT-GIT-2024-52006
CESA-2025_11534
CVE-2024-52006
DLA-4031-1
DSA-5850-1
GHSA-86C2-4X57-WC8G
GHSA-QM7J-C969-7J4Q
GHSA-R5PH-XG7Q-XFRP
INFSA-2025_11462
INFSA-2025_11534
MGASA-2025-0016
OESA-2025-1068
OPENSUSE-SU-2025_0116-1
OPENSUSE-SU-2025_0144-1
RHSA-2025:11462
RHSA-2025:11533
RHSA-2025:11534
RHSA-2025_11462
RHSA-2025_11534
SUSE-RU-2025:20362-1
SUSE-SU-2025:0116-1
SUSE-SU-2025:0144-1
SUSE-SU-2025:0197-1
SUSE-SU-2025:20197-1
SUSE-SU-2025:20721-1
SUSE-SU-2025_0197-1
USN-7207-1
USN-7207-2
USN-7964-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Git
Git Credential Manager
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu