CVE Vulnerabilities

CVE-2024-32004

Process Control

Published: May 14, 2024 | Modified: Jan 06, 2026
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.1 IMPORTANT
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid cloning repositories from untrusted sources.

Weakness

Executing commands or loading libraries from an untrusted source or in an untrusted environment can cause an application to execute malicious commands (and payloads) on behalf of an attacker.

Affected Software

NameVendorStart VersionEnd Version
GitGit-scm*2.39.4 (excluding)
GitGit-scm2.40.0 (including)2.40.2 (excluding)
GitGit-scm2.42.0 (including)2.42.2 (excluding)
GitGit-scm2.43.0 (including)2.43.4 (excluding)
GitGit-scm2.41.0 (including)2.41.0 (including)
GitGit-scm2.44.0 (including)2.44.0 (including)
GitGit-scm2.45.0 (including)2.45.0 (including)
Red Hat Enterprise Linux 8RedHatgit-0:2.43.5-1.el8_10*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatgit-0:2.18.4-5.el8_2*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatgit-0:2.27.0-5.el8_4*
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceRedHatgit-0:2.27.0-5.el8_4*
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsRedHatgit-0:2.27.0-5.el8_4*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatgit-0:2.31.8-3.el8_6*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatgit-0:2.31.8-3.el8_6*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatgit-0:2.31.8-3.el8_6*
Red Hat Enterprise Linux 8.8 Extended Update SupportRedHatgit-0:2.39.5-1.el8_8*
Red Hat Enterprise Linux 9RedHatgit-0:2.43.5-1.el9_4*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatgit-0:2.31.1-6.el9_0*
Red Hat Enterprise Linux 9.2 Extended Update SupportRedHatgit-0:2.39.5-1.el9_2*
GitUbuntudevel*
GitUbuntuesm-infra/bionic*
GitUbuntuesm-infra/focal*
GitUbuntufocal*
GitUbuntujammy*
GitUbuntumantic*
GitUbuntunoble*
GitUbuntuupstream*

Extended Description

Process control vulnerabilities of the first type occur when either data enters the application from an untrusted source and the data is used as part of a string representing a command that is executed by the application. By executing the command, the application gives an attacker a privilege or capability that the attacker would not otherwise have.

Potential Mitigations

References