CVE-2024-32004

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/05/2024
Last modified:
06/01/2026

Description

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid cloning repositories from untrusted sources.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* 2.39.4 (excluding)
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* 2.40.0 (including) 2.40.2 (excluding)
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* 2.42.0 (including) 2.42.2 (excluding)
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* 2.43.0 (including) 2.43.4 (excluding)
cpe:2.3:a:git-scm:git:2.41.0:*:*:*:*:*:*:*
cpe:2.3:a:git-scm:git:2.44.0:*:*:*:*:*:*:*
cpe:2.3:a:git-scm:git:2.45.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*