NA

CVE-2024-32004

Published: 14/05/2024 Updated: 14/05/2024

Vulnerability Summary

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid cloning repositories from untrusted sources.

Vulnerability Trend

Vendor Advisories

Debian Bug report logs - #1071160 git: CVE-2024-32002 CVE-2024-32004 CVE-2024-32020 CVE-2024-32021 CVE-2024-32465 Package: src:git; Maintainer for src:git is Jonathan Nieder <jrnieder@gmailcom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 15 May 2024 09:48:01 UTC Severity: grave Tags: security, ...
Git is a revision control system Prior to versions 2451, 2441, 2434, 2422, 2411, 2402, and 2394, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `git/` directory This allows writing a hook that will be executed w ...
Git is a revision control system Prior to versions 2451, 2441, 2434, 2422, 2411, 2402, and 2394, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `git/` directory This allows writing a hook that will be executed w ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> git: 5 vulnerabilities fixed <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Johannes Schindelin &lt;JohannesSch ...

Recent Articles

Microsoft May 2024 Patch Tuesday fixes 3 zero-days, 61 flaws
BleepingComputer • Lawrence Abrams • 14 May 2024

Microsoft May 2024 Patch Tuesday fixes 3 zero-days, 61 flaws By Lawrence Abrams May 14, 2024 01:49 PM 0 .crit { font-weight:bold; color:red; } .article_section td { font-size: 14px!important; } Today is Microsoft's May 2024 Patch Tuesday, which includes security updates for 61 flaws and three actively exploited or publicly disclosed zero days. This Patch Tuesday only fixes one critical vulnerability, a Microsoft SharePoint Server Remote Code Execution Vulnerability. The number of bugs in each vu...