Logo
vulnerabilityCVE-2024-32004
Name
CVE-2024-32004
Source
NVD ( link)Debian ( link)
Description
Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid cloning repositories from untrusted sources.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
git
Patched

Vulnerability Ratings#


8.1
CVSSv31
7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.48.2
Not Affected
buildroot
master
2.54.0
Not Affected
openwrt
master
2.50.1-r1
Not Affected
openwrt
openwrt-25.12
2.50.1-r1
Not Affected
yocto
master
2.54.0
Not Affected
yocto
scarthgap
2.44.4
Not Affected

Resolved with patches#


git (yocto:kirkstone)

#
Title
Author
Resolve
1
setup: prepare for more detailed "dubious ownership" messages
Johannes Schindelin <johannes.schindelin@gmx.de>
CVE-2024-32004
2
fetch/clone: detect dubious ownership of local repositories
Johannes Schindelin <johannes.schindelin@gmx.de>
CVE-2024-32004
3
t0411: add tests for cloning from partial repo
Filip Hejsek <filip.hejsek@gmail.com>
CVE-2024-32004