The sideband payload is passed unfiltered to the terminal in git
Published Jan 15, 2025
7.5
HIGHCVSS 4.0
EPSS 0.51%
Description
Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.
Affected products
-
- Version <= 2.40.4StatusaffectedConstraints-
- Version >= 2.41.0, <= 2.41.3StatusaffectedConstraints-
- Version >= 2.42.0, <= 2.42.4StatusaffectedConstraints-
- Version >= 2.43.0, <= 2.43.6StatusaffectedConstraints-
- Version >= 2.44.0, <= 2.44.3StatusaffectedConstraints-
- Version >= 2.45.0, <= 2.45.3StatusaffectedConstraints-
- Version >= 2.46.0, <= 2.46.3StatusaffectedConstraints-
- Version >= 2.47.0, <= 2.47.1StatusaffectedConstraints-
- Version >= 2.48.0, <= 2.48.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Git | Git | n/a |
|
- ≤ 2.40.4
- ≥ 2.41.0 · ≤ 2.41.3
- ≥ 2.42.0 · ≤ 2.42.4
- ≥ 2.43.0 · ≤ 2.43.6
- ≥ 2.44.0 · ≤ 2.44.3
- ≥ 2.45.0 · ≤ 2.45.3
- ≥ 2.46.0 · ≤ 2.46.3
- ≥ 2.47.0 · ≤ 2.47.1
- ≥ 2.48.0 · ≤ 2.48.1
No data.
Red Hat Discovery 1.14
discovery/discovery-server-rhel9:1.14.3-1748529279
Fixed · RHSA-2025:8385
Red Hat Enterprise Linux 10
git-0:2.47.1-2.el10_0
Fixed · RHSA-2025:7482
Red Hat Enterprise Linux 8
git-0:2.43.5-3.el8_10
Fixed · RHSA-2025:8414
Red Hat Enterprise Linux 9
git-0:2.47.1-2.el9_6
Fixed · RHSA-2025:7409
Red Hat Enterprise Linux 9.2 Extended Update Support
git-0:2.39.5-1.el9_2.1
Fixed · RHSA-2025:7641
Red Hat Enterprise Linux 9.4 Extended Update Support
git-0:2.43.5-1.el9_4.1
Fixed · RHSA-2025:7640
Red Hat Enterprise Linux 6
git
Out of support scope
Red Hat Enterprise Linux 7
git
Will not fix
Red Hat Fuse 7
io.syndesis-syndesis-parent
Out of support scope
Red Hat OpenShift Container Platform 4
rhcos
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Discovery 1.14 | discovery/discovery-server-rhel9:1.14.3-1748529279 | Fixed | RHSA-2025:8385 |
| Red Hat Enterprise Linux 10 | git-0:2.47.1-2.el10_0 | Fixed | RHSA-2025:7482 |
| Red Hat Enterprise Linux 8 | git-0:2.43.5-3.el8_10 | Fixed | RHSA-2025:8414 |
| Red Hat Enterprise Linux 9 | git-0:2.47.1-2.el9_6 | Fixed | RHSA-2025:7409 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | git-0:2.39.5-1.el9_2.1 | Fixed | RHSA-2025:7641 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | git-0:2.43.5-1.el9_4.1 | Fixed | RHSA-2025:7640 |
| Red Hat Enterprise Linux 6 | git | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | git | Will not fix | n/a |
| Red Hat Fuse 7 | io.syndesis-syndesis-parent | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | rhcos | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is classified as moderate rather than important because it primarily affects informational messages rather than directly compromising repository integrity or executing arbitrary code. The issue arises from Git's failure to sanitize ANSI escape sequences in messages received over the sideband channel, which could allow a malicious remote repository to manipulate terminal output. However, exploitation requires user interaction, such as manually copying and executing misleading commands. Unlike higher-severity vulnerabilities, this does not provide direct unauthorized access, remote code execution, or privilege escalation, limiting its overall impact. The risk is further mitigated by best practices, such as avoiding recursive clones from untrusted sources.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2024-52005 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2338289 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-46250 Advisory
- https://github.com/git/git/security/advisories/GHSA-7jjc-gg6m-3329 x_refsource_CONFIRMVendor Advisory
- https://lore.kernel.org/git/1M9FnZ-1taoNo1wwh-00ESSd@mail.gmx.net x_refsource_MISCMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-52005
- https://www.cve.org/CVERecord?id=CVE-2024-52005
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-52005 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2338289 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-46250 | Advisory | |
| https://github.com/git/git/security/advisories/GHSA-7jjc-gg6m-3329 | x_refsource_CONFIRMVendor Advisory | |
| https://lore.kernel.org/git/1M9FnZ-1taoNo1wwh-00ESSd@mail.gmx.net | x_refsource_MISCMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-52005 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-52005 |
Change history (0)
No recorded changes yet.