← Back

CVE-2024-32478

nvd nist
Published: Apr 19, 2024Modified: Nov 21, 2024

JSON object

Loading...
6.9
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N
Exploitability: 0.6 / Impact: 5.8
Source: security-advisories@github.com (Secondary)

Description

Git Credential Manager (GCM) is a secure Git credential helper. Prior to 2.5.0, the Debian package does not set root ownership on installed files. This allows user 1001 on a multi-user system can replace binary and gain other users' privileges. This vulnerability is fixed in 2.5.0.

Timeline

No history available yet.