Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-32002

Опубликовано: 14 мая 2024
Источник: redhat
CVSS3: 9
EPSS Высокий

Описание

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a .git/ directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is disabled in Git (e.g. via git config --global core.symlinks false), the described attack won't work. As always, it is best to avoid cloning repositories from untrusted sources.

A vulnerability was found in Git. This vulnerability allows the malicious manipulation of repositories containing submodules, exploiting a bug that enables the writing of files into the .git/ directory instead of the submodule's intended worktree. This manipulation facilitates the execution of arbitrary code during the cloning process, bypassing user inspection and control.

Отчет

While the described bug in Git presents a significant security concern, it falls short of being categorized as Critical due to several factors. The exploit requires a specific set of conditions, such as repositories with submodules and the presence of symbolic link support. Additionally, successful exploitation relies on users cloning repositories from untrusted sources, limiting its scope compared to critical vulnerabilities that may be remotely exploitable or affect a broader range of use cases. However, the potential impact of remote code execution during cloning operations underscores the importance of promptly applying patches and exercising caution when interacting with Git repositories, emphasizing its significant severity within the realm of software security.

Меры по смягчению последствий

One preventative measure is to disable symbolic link support. This can be accomplished by running the command git config --global core.symlinks false. Another temporary option is to avoid using the --recurse-submodules setting with untrusted git repos.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gitAffected
Red Hat Enterprise Linux 6gitOut of support scope
Red Hat Enterprise Linux 7gitWill not fix
Red Hat Fuse 7gitWill not fix
Red Hat Software Collectionsrh-git227-gitAffected
Red Hat Enterprise Linux 8gitFixedRHSA-2024:408425.06.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportgitFixedRHSA-2024:602829.08.2024
Red Hat Enterprise Linux 8.4 Telecommunications Update ServicegitFixedRHSA-2024:602829.08.2024
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsgitFixedRHSA-2024:602829.08.2024
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportgitFixedRHSA-2024:602729.08.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22->CWE-434

EPSS

Процентиль: 99%
0.73193
Высокий

9 Critical

CVSS3

Связанные уязвимости

CVSS3: 9
ubuntu
около 1 года назад

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is disabled in Git (e.g. via `git config --global core.symlinks false`), the described attack won't work. As always, it is best to avoid cloning repositories from untrusted sources.

CVSS3: 9
nvd
около 1 года назад

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is disabled in Git (e.g. via `git config --global core.symlinks false`), the described attack won't work. As always, it is best to avoid cloning repositories from untrusted sources.

CVSS3: 9
msrc
около 1 года назад

GitHub: CVE-2024-32002 Recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution

CVSS3: 9
debian
около 1 года назад

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2. ...

CVSS3: 9
fstec
около 1 года назад

Уязвимость распределенной системы контроля версий Git, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 99%
0.73193
Высокий

9 Critical

CVSS3