Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2024-32004

HIGH 8.1 Vendor bulletin scale — NVD CVSS pending

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid cloning repositories from untrusted sources.

Attack vector : Local No privileges required No user interaction
Show raw CVSS vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS 1.35% above median percentile 68.9%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

  • Git Windows winget:Git.Git
    Affected Fixed in Latest tracked 2.55.0.3 undetermined
Vulnerable CPE configurations (7)
Vendor Product Versions
git-scm git
All platforms (wildcard)
<2.39.4
git-scm git
All platforms (wildcard)
≥2.40.0 <2.40.2
git-scm git
All platforms (wildcard)
≥2.42.0 <2.42.2
git-scm git
All platforms (wildcard)
≥2.43.0 <2.43.4
git-scm git
All platforms (wildcard)
git-scm git
All platforms (wildcard)
git-scm git
All platforms (wildcard)
View on NVD ↗ Advisory · github.com Advisory · lists.debian.org Advisory · lists.fedoraproject.org