← Back

CVE-2024-32004

nvd nist
Published: May 14, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid cloning repositories from untrusted sources.

Affected (10)

1 product
Git
1 product
Fedora
1 product
Debian Linux
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Git Scm
Before 2.39.4
From 2.40.0 to 2.40.2
From 2.42.0 to 2.42.2
From 2.43.0 to 2.43.4
Version 2.41.0
Version 2.44.0
Version 2.45.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 40
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 11.0

References (13)

Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Technical Description
Source: security-advisories@github.com
Vendor Advisory
Source: security-advisories@github.com
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Technical Description
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory

Timeline

No history available yet.