Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 17

Количество 17

fstec логотип

BDU:2024-04042

больше 2 лет назад

Уязвимость распределенной системы контроля версий Git, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю обойти защиту при клонировании ненадежных репозиториев

CVSS3: 7.3
EPSS: Низкий
redos логотип

ROS-20240527-04

больше 2 лет назад

Множественные уязвимости git

CVSS3: 8.1
EPSS: Низкий
altlinux логотип

ALT-PU-2024-17907

больше 1 года назад

ALT-PU-2024-17907: package `git` update to version 2.42.2-alt1

CVSS3: 9
EPSS: Низкий
altlinux логотип

ALT-PU-2024-8904

больше 2 лет назад

ALT-PU-2024-8904: package `git` update to version 2.42.2-alt1

CVSS3: 9
EPSS: Низкий
ubuntu логотип

CVE-2024-32465

больше 2 лет назад

Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the context of cloning local repositories owned by other users, this vulnerability has been covered in CVE-2024-32004. But there are circumstances where the fixes for CVE-2024-32004 are not enough: For example, when obtaining a `.zip` file containing a full copy of a Git repository, it should not be trusted by default to be safe, as e.g. hooks could be configured to run within the context of that repository. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid using Git in repositories that have been obtained via archives from untrusted sources.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2024-32465

больше 2 лет назад

Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the context of cloning local repositories owned by other users, this vulnerability has been covered in CVE-2024-32004. But there are circumstances where the fixes for CVE-2024-32004 are not enough: For example, when obtaining a `.zip` file containing a full copy of a Git repository, it should not be trusted by default to be safe, as e.g. hooks could be configured to run within the context of that repository. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid using Git in repositories that have been obtained via archives from untrusted sources.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2024-32465

больше 2 лет назад

Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the context of cloning local repositories owned by other users, this vulnerability has been covered in CVE-2024-32004. But there are circumstances where the fixes for CVE-2024-32004 are not enough: For example, when obtaining a `.zip` file containing a full copy of a Git repository, it should not be trusted by default to be safe, as e.g. hooks could be configured to run within the context of that repository. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid using Git in repositories that have been obtained via archives from untrusted sources.

CVSS3: 7.3
EPSS: Низкий
msrc логотип

CVE-2024-32465

около 2 лет назад

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2024-32465

больше 2 лет назад

Git is a revision control system. The Git project recommends to avoid ...

CVSS3: 7.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2277-1

около 2 лет назад

Security update for git

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1854-1

больше 2 лет назад

Security update for git

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1807-1

больше 2 лет назад

Security update for git

EPSS: Низкий
rocky логотип

RLSA-2024:4084

около 2 лет назад

Important: git security update

EPSS: Низкий
rocky логотип

RLSA-2024:4083

около 2 лет назад

Important: git security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4084

больше 2 лет назад

ELSA-2024-4084: git security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4083

больше 2 лет назад

ELSA-2024-4083: git security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0197-1

больше 1 года назад

Security update for git

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-04042

Уязвимость распределенной системы контроля версий Git, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю обойти защиту при клонировании ненадежных репозиториев

CVSS3: 7.3
1%
Низкий
больше 2 лет назад
redos логотип
ROS-20240527-04

Множественные уязвимости git

CVSS3: 8.1
больше 2 лет назад
altlinux логотип
ALT-PU-2024-17907

ALT-PU-2024-17907: package `git` update to version 2.42.2-alt1

CVSS3: 9
больше 1 года назад
altlinux логотип
ALT-PU-2024-8904

ALT-PU-2024-8904: package `git` update to version 2.42.2-alt1

CVSS3: 9
больше 2 лет назад
ubuntu логотип
CVE-2024-32465

Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the context of cloning local repositories owned by other users, this vulnerability has been covered in CVE-2024-32004. But there are circumstances where the fixes for CVE-2024-32004 are not enough: For example, when obtaining a `.zip` file containing a full copy of a Git repository, it should not be trusted by default to be safe, as e.g. hooks could be configured to run within the context of that repository. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid using Git in repositories that have been obtained via archives from untrusted sources.

CVSS3: 7.3
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32465

Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the context of cloning local repositories owned by other users, this vulnerability has been covered in CVE-2024-32004. But there are circumstances where the fixes for CVE-2024-32004 are not enough: For example, when obtaining a `.zip` file containing a full copy of a Git repository, it should not be trusted by default to be safe, as e.g. hooks could be configured to run within the context of that repository. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid using Git in repositories that have been obtained via archives from untrusted sources.

CVSS3: 7.3
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-32465

Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the context of cloning local repositories owned by other users, this vulnerability has been covered in CVE-2024-32004. But there are circumstances where the fixes for CVE-2024-32004 are not enough: For example, when obtaining a `.zip` file containing a full copy of a Git repository, it should not be trusted by default to be safe, as e.g. hooks could be configured to run within the context of that repository. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid using Git in repositories that have been obtained via archives from untrusted sources.

CVSS3: 7.3
1%
Низкий
больше 2 лет назад
msrc логотип
CVSS3: 7.3
1%
Низкий
около 2 лет назад
debian логотип
CVE-2024-32465

Git is a revision control system. The Git project recommends to avoid ...

CVSS3: 7.3
1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:2277-1

Security update for git

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1854-1

Security update for git

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1807-1

Security update for git

больше 2 лет назад
rocky логотип
RLSA-2024:4084

Important: git security update

около 2 лет назад
rocky логотип
RLSA-2024:4083

Important: git security update

около 2 лет назад
oracle-oval логотип
ELSA-2024-4084

ELSA-2024-4084: git security update (IMPORTANT)

больше 2 лет назад
oracle-oval логотип
ELSA-2024-4083

ELSA-2024-4083: git security update (IMPORTANT)

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2025:0197-1

Security update for git

больше 1 года назад

Уязвимостей на страницу