Improper Encoding or Escaping of Output in Git - CVE-2024-52006

 

Improper Encoding or Escaping of Output in Git - CVE-2024-52006

Published: January 16, 2025


Vulnerability identifier: #VU102869
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-52006
CWE-ID: CWE-116
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to exfiltrate data.

The vulnerability exists due to newline confusion in credential helpers when interpreting single Carriage Return characters. A remote attacker can gain access to sensitive information.


Affected software

Git
Red Hat OpenShift Container Platform
Debian Linux
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Slackware Linux
Development Tools Module
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Git for Windows
Storage Resource Manager
IBM Qradar SIEM
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
git (Ubuntu package)
git-daemon-debuginfo
git
git-debugsource
git-svn
git-daemon
git-core
git-email
git-cvs
git-core-debuginfo
git-web
gitk
git-gui
git-credential-gnome-keyring
git-debuginfo
git-credential-libsecret-debuginfo
git-credential-libsecret
perl-Git
git-credential-gnome-keyring-debuginfo
git-arch
git-p4
git-doc
git (Debian package)
perl-Git-SVN
git-help
git (Red Hat package)
git-instaweb
git-core-doc
git-all
git-subtree
gitweb
Dell EMC Storage Monitoring and Reporting (SMR)

How to mitigate CVE-2024-52006

Install updates from vendor's website.

Git - addressed in versions 2.40.4, 2.41.3, 2.42.4, 2.43.6, 2.44.3, 2.45.3, 2.46.3, 2.47.1, 2.48.1
Git for Windows - addressed in versions 2.45.2.2, 2.46.2.2, 2.47.1.2
IBM Qradar SIEM - update to 7.5.0 Update Pack 13 IF01
Ansible Automation Platform - update to 2.5
git (Ubuntu package) - addressed in versions 1:2.7.4-0ubuntu1.10+esm13, 1:2.17.1-1ubuntu0.18+esm6, 1:2.25.1-1ubuntu3.14, 1:2.34.1-1ubuntu1.12, 1:2.43.0-1ubuntu7.2, 1:2.45.2-1ubuntu1.1
Red Hat Advanced Cluster Management for Kubernetes - update to 2.13.4
git-daemon-debuginfo - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.48.1, 2.43.0-150600.3.9.1
git - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.48.1, 2.43.0-150600.3.9.1
git-debugsource - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.48.1, 2.43.0-150600.3.9.1
git-svn - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.48.1, 2.43.0-150600.3.9.1
git-daemon - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.48.1, 2.43.0-150600.3.9.1
git-core - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.48.1, 2.43.0-150600.3.9.1
git-email - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.48.1, 2.43.0-150600.3.9.1
git-cvs - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.48.1, 2.43.0-150600.3.9.1
git-core-debuginfo - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.48.1, 2.43.0-150600.3.9.1
git-web - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.48.1, 2.43.0-150600.3.9.1
gitk - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.48.1, 2.43.0-150600.3.9.1
git-gui - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.48.1, 2.43.0-150600.3.9.1
git-credential-gnome-keyring - update to 2.35.3-150300.10.48.1
git-debuginfo - addressed in versions 2.35.3-150300.10.48.1, 2.43.0-150600.3.9.1
git-credential-libsecret-debuginfo - addressed in versions 2.35.3-150300.10.48.1, 2.43.0-150600.3.9.1
git-credential-libsecret - addressed in versions 2.35.3-150300.10.48.1, 2.43.0-150600.3.9.1
perl-Git - addressed in versions 2.35.3-150300.10.48.1, 2.43.0-150600.3.9.1
git-credential-gnome-keyring-debuginfo - update to 2.35.3-150300.10.48.1
git-arch - addressed in versions 2.35.3-150300.10.48.1, 2.43.0-150600.3.9.1
git-p4 - addressed in versions 2.35.3-150300.10.48.1, 2.43.0-150600.3.9.1
git-doc - addressed in versions 2.35.3-150300.10.48.1, 2.43.0-150600.3.9.1
git (Debian package) - update to 1:2.39.5-0+deb12u2
git-svn - update to 2.43.0-6
git-web - update to 2.43.0-6
gitk - update to 2.43.0-6
perl-Git - update to 2.43.0-6
perl-Git-SVN - update to 2.43.0-6
git-help - update to 2.43.0-6
git-gui - update to 2.43.0-6
git-email - update to 2.43.0-6
git-debugsource - update to 2.43.0-6
git-debuginfo - update to 2.43.0-6
git-daemon - update to 2.43.0-6
git-core - update to 2.43.0-6
git - update to 2.43.0-6
git (Red Hat package) - addressed in versions 2.43.7-1.el8_10, 2.47.3-1.el9_6, 2.47.3-1.el10_0
git-credential-libsecret - update to 2.43.7-1.0.1
git-svn - update to 2.43.7-1.0.1
git-instaweb - update to 2.43.7-1.0.1
git-gui - update to 2.43.7-1.0.1
git-email - update to 2.43.7-1.0.1
git-core-doc - update to 2.43.7-1.0.1
git-all - update to 2.43.7-1.0.1
git-subtree - update to 2.43.7-1.0.1
git-daemon - update to 2.43.7-1.0.1
git-core - update to 2.43.7-1.0.1
git - update to 2.43.7-1.0.1
gitk - update to 2.43.7-1.0.1
gitweb - update to 2.43.7-1.0.1
perl-Git - update to 2.43.7-1.0.1
perl-Git-SVN - update to 2.43.7-1.0.1
git - update to 2.46.3
Red Hat OpenShift Container Platform - addressed in versions 4.14.54, 4.15.56, 4.19.6
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 5.0.2.2, 5.1.0.0
Storage Resource Manager - addressed in versions 5.0.2.2, 5.1.0.0

External References

Related Security Bulletins