Improper Encoding or Escaping of Output in Git for Windows - CVE-2024-52005

 

Improper Encoding or Escaping of Output in Git for Windows - CVE-2024-52005

Published: January 16, 2025


Vulnerability identifier: #VU102871
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-52005
CWE-ID: CWE-116
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper input validation when handling ANSI escape sequences in messages  passed via sideband channel. A remote attacker can pass specially crafted messages to the terminal and potentially execute untrusted scripts.


Affected software

Git for Windows
IBM Cloud Pak for Watson AIOps
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
openEuler
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
git-core
git
perl-Git-SVN
perl-Git
gitk
git-web
git-help
git-gui
git-email
git-debugsource
git-debuginfo
git-daemon
git-svn
git (Red Hat package)
git-core-doc
git-instaweb
gitweb
git-all
git-subtree
git-credential-libsecret
git-p4
Red Hat OpenShift GitOps
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces

How to mitigate CVE-2024-52005

Install updates from vendor's website.

Git for Windows - addressed in versions 2.45.2.2, 2.46.2.2, 2.47.1.2
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 12 IF03
Juniper Secure Analytics (JSA) - update to 7.5.0 UP12 IF03
Red Hat OpenShift GitOps - addressed in versions 1.15.3, 1.16.1
IBM Cloud Pak for Multicloud Management - update to 2.3 Fix Pack 12
Ansible Automation Platform - update to 2.4
Red Hat Advanced Cluster Management for Kubernetes - update to 2.13.3
git-core - update to 2.33.0-17
git - update to 2.33.0-17
perl-Git-SVN - update to 2.33.0-17
perl-Git - update to 2.33.0-17
gitk - update to 2.33.0-17
git-web - update to 2.33.0-17
git-help - update to 2.33.0-17
git-gui - update to 2.33.0-17
git-email - update to 2.33.0-17
git-debugsource - update to 2.33.0-17
git-debuginfo - update to 2.33.0-17
git-daemon - update to 2.33.0-17
git-svn - update to 2.33.0-17
git (Red Hat package) - addressed in versions 2.39.5-1.el9_2.1, 2.43.5-1.el9_4.1, 2.43.5-3.el8_10, 2.47.1-2.el9_6
git-core-doc - addressed in versions 2.43.5-3, 2.47.3-1
git-email - addressed in versions 2.43.5-3, 2.47.3-1
git-gui - addressed in versions 2.43.5-3, 2.47.3-1
git-instaweb - addressed in versions 2.43.5-3, 2.47.3-1
git-svn - addressed in versions 2.43.5-3, 2.47.3-1
gitk - addressed in versions 2.43.5-3, 2.47.3-1
perl-Git-SVN - addressed in versions 2.43.5-3, 2.47.3-1
gitweb - addressed in versions 2.43.5-3, 2.47.3-1
perl-Git - addressed in versions 2.43.5-3, 2.47.3-1
git-all - addressed in versions 2.43.5-3, 2.47.3-1
git-subtree - addressed in versions 2.43.5-3, 2.47.3-1
git-daemon - addressed in versions 2.43.5-3, 2.47.3-1
git-credential-libsecret - addressed in versions 2.43.5-3, 2.47.3-1
git-core - addressed in versions 2.43.5-3, 2.47.3-1
git - addressed in versions 2.43.5-3, 2.47.3-1
git-p4 - update to 2.47.3-1
Red Hat OpenShift Dev Spaces - update to 3.21.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.77, 4.15.53, 4.18.14, 4.19.0

External References

Related Security Bulletins