Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-32004

Опубликовано: 14 мая 2024
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid cloning repositories from untrusted sources.

A vulnerability was found in Git. This vulnerability can be exploited by an unauthenticated attacker who places a specialized repository on the target's local system. If the victim clones this repository, the attacker can execute arbitrary code.

Отчет

This vulnerability, while significant, does not reach Critical severity due to its reliance on local repository manipulation. While it allows attackers to execute arbitrary code during cloning operations, its impact is constrained by the necessity for access to the target's local environment. Critical severity typically involves vulnerabilities that can be exploited remotely or without user interaction. Nonetheless, this issue remains Important as it can lead to unauthorized code execution, potentially compromising the integrity and security of affected systems. Fuse 7 Karaf uses JGit to manage patches. It's heavily protected by file permissions and RBAC. Unless an attacker have write permissions to Fuse internal git repositories, this vulnerability is not exploitable.

Меры по смягчению последствий

Exercise caution when cloning repositories from untrusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gitAffected
Red Hat Enterprise Linux 6gitOut of support scope
Red Hat Enterprise Linux 7gitNot affected
Red Hat Fuse 7gitOut of support scope
Red Hat Software Collectionsrh-git227-gitAffected
Red Hat Enterprise Linux 8gitFixedRHSA-2024:408425.06.2024
Red Hat Enterprise Linux 8.2 Advanced Update SupportgitFixedRHSA-2024:770107.10.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportgitFixedRHSA-2024:602829.08.2024
Red Hat Enterprise Linux 8.4 Telecommunications Update ServicegitFixedRHSA-2024:602829.08.2024
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsgitFixedRHSA-2024:602829.08.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-114
https://bugzilla.redhat.com/show_bug.cgi?id=2280428git: RCE while cloning local repos

EPSS

Процентиль: 77%
0.01076
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 1 года назад

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid cloning repositories from untrusted sources.

CVSS3: 8.1
nvd
около 1 года назад

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid cloning repositories from untrusted sources.

CVSS3: 8.1
msrc
около 1 года назад

GitHub: CVE-2024-32004 Remote Code Execution while cloning special-crafted local repositories

CVSS3: 8.1
debian
около 1 года назад

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2. ...

CVSS3: 8.1
fstec
около 1 года назад

Уязвимость распределенной системы контроля версий Git, существующая из-за проблемы с управлением процессом, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 77%
0.01076
Низкий

8.1 High

CVSS3