CVE-2024-32004: Git vulnerable to Remote Code Execution while cloning special-crafted local repositories
An attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation.
Other sources
GitHub: CVE-2024-32004 Remote Code Execution while cloning special-crafted local repositories
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/gitto a version that resolves this vulnerability.Fixed in 1:2.30.2-1+deb11u4Fixed in 1:2.39.5-0+deb12u2Fixed in 1:2.47.2-0.1Fixed in 1:2.49.0-1 - Upgrade
Upgrade
redhat/gitto a version that resolves this vulnerability.Fixed in 2.45.1 - Upgrade
Upgrade
redhat/gitto a version that resolves this vulnerability.Fixed in 2.44.1 - Upgrade
Upgrade
redhat/gitto a version that resolves this vulnerability.Fixed in 2.43.4 - Upgrade
Upgrade
redhat/gitto a version that resolves this vulnerability.Fixed in 2.42.2 - Upgrade
Upgrade
redhat/gitto a version that resolves this vulnerability.Fixed in 2.41.1 - Upgrade
Upgrade
redhat/gitto a version that resolves this vulnerability.Fixed in 2.40.2 - Upgrade
Upgrade
redhat/gitto a version that resolves this vulnerability.Fixed in 2.39.4 - Upgrade
Upgrade
Gitto a version that resolves this vulnerability.Fixed in 2.45.1 - Upgrade
Upgrade
Gitto a version that resolves this vulnerability.Fixed in 2.44.1 - Upgrade
Upgrade
Gitto a version that resolves this vulnerability.Fixed in 2.43.4 - Upgrade
Upgrade
Gitto a version that resolves this vulnerability.Fixed in 2.42.2 - Upgrade
Upgrade
Gitto a version that resolves this vulnerability.Fixed in 2.41.1 - Upgrade
Upgrade
Gitto a version that resolves this vulnerability.Fixed in 2.40.2 - Upgrade
Upgrade
Gitto a version that resolves this vulnerability.Fixed in 2.39.4 - Compensating control
Avoid cloning repositories from untrusted sources (workaround for CVE-2024-32004).
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32004?
CVE-2024-32004 is classified as a high severity vulnerability due to the potential for arbitrary code execution when a manipulated repository is cloned.
How do I fix CVE-2024-32004?
To fix CVE-2024-32004, upgrade to Git versions 2.45.2 or later, or apply patches as specified in your software vendor's release notes.
Which versions of Git are vulnerable to CVE-2024-32004?
CVE-2024-32004 affects Git versions prior to 2.45.1, including 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4.
Can third-party tools be affected by CVE-2024-32004?
Yes, third-party tools that leverage the affected versions of Git may be at risk of exploitation via CVE-2024-32004.
Is Visual Studio impacted by CVE-2024-32004?
Yes, Microsoft Visual Studio versions that include vulnerable Git components are affected by CVE-2024-32004 and should be updated.