Git vulnerable to Remote Code Execution while cloning special-crafted local repositories
Published May 14, 2024
8.2
HIGHCVSS 3.1
EPSS 1.35%
Description
Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid cloning repositories from untrusted sources.
Affected products
-
- Version < 2.39.4StatusaffectedConstraints-
- Version = 2.41.0StatusaffectedConstraints-
- Version = 2.44.0StatusaffectedConstraints-
- Version = 2.45.0StatusaffectedConstraints-
- Version >= 2.40.0, < 2.40.2StatusaffectedConstraints-
- Version >= 2.42.0, < 2.42.2StatusaffectedConstraints-
- Version >= 2.43.0, < 2.43.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 1
Configuration 2
- 40
Configuration 3
- 10.0
- 11.0
-
- Version 0StatusaffectedConstraints<2.39.4
- Version 2.40.0StatusaffectedConstraints<2.40.2
- Version 2.41.0StatusaffectedConstraints-
- Version 2.42.0StatusaffectedConstraints<2.42.2
- Version 2.43.0StatusaffectedConstraints<2.43.4
- Version 2.44.0StatusaffectedConstraints-
- Version 2.45.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Red Hat Enterprise Linux 8
git-0:2.43.5-1.el8_10
Fixed · RHSA-2024:4084
Red Hat Enterprise Linux 8.2 Advanced Update Support
git-0:2.18.4-5.el8_2
Fixed · RHSA-2024:7701
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
git-0:2.27.0-5.el8_4
Fixed · RHSA-2024:6028
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
git-0:2.27.0-5.el8_4
Fixed · RHSA-2024:6028
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
git-0:2.27.0-5.el8_4
Fixed · RHSA-2024:6028
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
git-0:2.31.8-3.el8_6
Fixed · RHSA-2024:6027
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
git-0:2.31.8-3.el8_6
Fixed · RHSA-2024:6027
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
git-0:2.31.8-3.el8_6
Fixed · RHSA-2024:6027
Red Hat Enterprise Linux 8.8 Extended Update Support
git-0:2.39.5-1.el8_8
Fixed · RHSA-2024:4579
Red Hat Enterprise Linux 9
git-0:2.43.5-1.el9_4
Fixed · RHSA-2024:4083
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
git-0:2.31.1-6.el9_0
Fixed · RHSA-2024:6610
Red Hat Enterprise Linux 9.2 Extended Update Support
git-0:2.39.5-1.el9_2
Fixed · RHSA-2024:4368
Red Hat Enterprise Linux 10
git
Not affected
Red Hat Enterprise Linux 6
git
Out of support scope
Red Hat Enterprise Linux 7
git
Not affected
Red Hat Fuse 7
git
Out of support scope
Red Hat Software Collections
rh-git227-git
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | git-0:2.43.5-1.el8_10 | Fixed | RHSA-2024:4084 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | git-0:2.18.4-5.el8_2 | Fixed | RHSA-2024:7701 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | git-0:2.27.0-5.el8_4 | Fixed | RHSA-2024:6028 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | git-0:2.27.0-5.el8_4 | Fixed | RHSA-2024:6028 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | git-0:2.27.0-5.el8_4 | Fixed | RHSA-2024:6028 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | git-0:2.31.8-3.el8_6 | Fixed | RHSA-2024:6027 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | git-0:2.31.8-3.el8_6 | Fixed | RHSA-2024:6027 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | git-0:2.31.8-3.el8_6 | Fixed | RHSA-2024:6027 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | git-0:2.39.5-1.el8_8 | Fixed | RHSA-2024:4579 |
| Red Hat Enterprise Linux 9 | git-0:2.43.5-1.el9_4 | Fixed | RHSA-2024:4083 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | git-0:2.31.1-6.el9_0 | Fixed | RHSA-2024:6610 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | git-0:2.39.5-1.el9_2 | Fixed | RHSA-2024:4368 |
| Red Hat Enterprise Linux 10 | git | Not affected | n/a |
| Red Hat Enterprise Linux 6 | git | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | git | Not affected | n/a |
| Red Hat Fuse 7 | git | Out of support scope | n/a |
| Red Hat Software Collections | rh-git227-git | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability, while significant, does not reach Critical severity due to its reliance on local repository manipulation. While it allows attackers to execute arbitrary code during cloning operations, its impact is constrained by the necessity for access to the target's local environment. Critical severity typically involves vulnerabilities that can be exploited remotely or without user interaction. Nonetheless, this issue remains Important as it can lead to unauthorized code execution, potentially compromising the integrity and security of affected systems. Fuse 7 Karaf uses JGit to manage patches. It's heavily protected by file permissions and RBAC. Unless an attacker have write permissions to Fuse internal git repositories, this vulnerability is not exploitable.
Red Hat mitigation
Exercise caution when cloning repositories from untrusted sources.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
2 other sources (GitHub, Red Hat) ▾
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed May 15, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 1.35% (0.01351) | 70.56th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.27% (0.01271) | 65.92th | v5 (v2026.06.15) |
| Jan 7, 2026 | 2.63% (0.02631) | 85.27th | v4 (v2025.03.14) |
| Nov 21, 2025 | 6.80% (0.06805) | 90.93th | v4 (v2025.03.14) |
| Nov 18, 2025 | 4.00% (0.03997) | 87.29th | v4 (v2025.03.14) |
| Nov 5, 2025 | 6.64% (0.06635) | 90.78th | v4 (v2025.03.14) |
| Jun 23, 2025 | 8.04% (0.08038) | 91.67th | v4 (v2025.03.14) |
| Jun 22, 2025 | 7.00% (0.06999) | 91.00th | v4 (v2025.03.14) |
| Apr 15, 2025 | 1.08% (0.01076) | 76.54th | v4 (v2025.03.14) |
| Mar 30, 2025 | 4.00% (0.03997) | 87.35th | v4 (v2025.03.14) |
| Mar 29, 2025 | 14.17% (0.14175) | 90.64th | v4 (v2025.03.14) |
| Mar 28, 2025 | 4.00% (0.03997) | 87.36th | v4 (v2025.03.14) |
| Mar 25, 2025 | 14.17% (0.14175) | 93.73th | v4 (v2025.03.14) |
| Mar 20, 2025 | 4.00% (0.03997) | 87.43th | v4 (v2025.03.14) |
| Mar 19, 2025 | 14.17% (0.14175) | 93.55th | v4 (v2025.03.14) |
| Mar 17, 2025 | 4.00% (0.03997) | 87.65th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 12.17th | v3 (v2023.03.01) |
| Jun 27, 2024 | 0.04% (0.00044) | 10.44th | v3 (v2023.03.01) |
| May 15, 2024 | 0.04% (0.00045) | 14.63th | v3 (v2023.03.01) |
References (11)
- http://www.openwall.com/lists/oss-security/2024/05/14/2 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2024-32004 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2280428 Issue Tracking
- https://git-scm.com/docs/git-clone x_refsource_MISCTechnical Description
- https://github.com/git/git/commit/f4aa8c8bb11dae6e769cd930565173808cbb69c8 x_refsource_MISCPatch
- https://github.com/git/git/security/advisories/GHSA-xfc6-vwr8-r389 x_refsource_CONFIRMVendor Advisory
- https://lists.debian.org/debian-lts-announce/2024/06/msg00018.html Mailing ListVendor Advisory
- https://lists.debian.org/debian-lts-announce/2024/09/msg00009.html Mailing ListVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S4CK4IYTXEOBZTEM5K3T6LWOIZ3S44AR/ Mailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-32004
- https://www.cve.org/CVERecord?id=CVE-2024-32004
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2024/05/14/2 | Mailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2024-32004 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2280428 | Issue Tracking | |
| https://git-scm.com/docs/git-clone | x_refsource_MISCTechnical Description | |
| https://github.com/git/git/commit/f4aa8c8bb11dae6e769cd930565173808cbb69c8 | x_refsource_MISCPatch | |
| https://github.com/git/git/security/advisories/GHSA-xfc6-vwr8-r389 | x_refsource_CONFIRMVendor Advisory | |
| https://lists.debian.org/debian-lts-announce/2024/06/msg00018.html | Mailing ListVendor Advisory | |
| https://lists.debian.org/debian-lts-announce/2024/09/msg00009.html | Mailing ListVendor Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S4CK4IYTXEOBZTEM5K3T6LWOIZ3S44AR/ | Mailing ListVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-32004 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-32004 |
Change history (0)
No recorded changes yet.