Code Injection in Git - CVE-2024-32004

 

Code Injection in Git - CVE-2024-32004

Published: May 15, 2024 / Updated: June 7, 2024


Vulnerability identifier: #VU89490
CSH Severity: High
CVSS v4 BT: 7.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2024-32004
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a process control issue while cloning special-crafted local repositories. A remote attacker can execute arbitrary code on the target system.


Affected software

Git
Migration Toolkit for Containers
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
Amazon Linux AMI
Oracle Linux
Debian Linux
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Slackware Linux
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
Development Tools Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Oracle Solaris
Voice Gateway
Git for Windows
OpenManage Network Integration (OMNI)
Storage Resource Manager
Juniper Secure Analytics (JSA)
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
git (Ubuntu package)
swiftlint
git (Red Hat package)
git-daemon
git-gui
gitk
git-web
git-core-debuginfo
git-cvs
git-email
git
git-daemon-debuginfo
git-debugsource
git-svn
git-core
perl-Git-SVN
git-help
git-debuginfo
perl-Git
git-p4
git-doc
git-arch
git-credential-gnome-keyring
git-credential-gnome-keyring-debuginfo
git-credential-libsecret
git-credential-libsecret-debuginfo
git (Debian package)
gitweb
git-instaweb
git-core-doc
git-all
git-subtree
Juniper Junos Space
Visual Studio
Red Hat OpenShift GitOps
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
OpenShift Logging
IBM Cloud Pak for Business Automation
Autodesk Infraworks
Dell EMC Storage Monitoring and Reporting (SMR)

How to mitigate CVE-2024-32004

Install updates from vendor's website.

Git - addressed in versions 2.39.4, 2.40.2, 2.41.1, 2.42.2, 2.43.4, 2.44.1, 2.45.1
Voice Gateway - update to 1.0.8.12
Git for Windows - addressed in versions 2.39.4.1, 2.43.4.1, 2.44.1.1, 2.45.1.1
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Juniper Junos Space - update to 24.1R3
git (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:2.25.1-1ubuntu3.12, 1:2.34.1-1ubuntu1.11, 1:2.40.1-1ubuntu1.1, 1:2.43.0-1ubuntu7.1
swiftlint - update to 0.57.1-1.fc42
Migration Toolkit for Containers - update to 1.8.4
Red Hat OpenShift GitOps - addressed in versions 1.11.6, 1.12.5, 1.13.1
IBM Cloud Pak for Multicloud Management - update to 2.3 FP11
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.7, 2.9.5, 2.10.4
git (Red Hat package) - addressed in versions 2.18.4-5.el8_2, 2.31.1-6.el9_0, 2.39.5-1.el8_8, 2.43.5-1.el8_10, 2.43.5-1.el9_4
git-daemon - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-gui - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
gitk - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-web - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-core-debuginfo - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-cvs - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-email - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-daemon-debuginfo - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-debugsource - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-svn - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-core - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
perl-Git-SVN - update to 2.27.0-17
git-help - update to 2.27.0-17
git-svn - update to 2.27.0-17
git-debuginfo - update to 2.27.0-17
git-daemon - update to 2.27.0-17
git-debugsource - update to 2.27.0-17
git - update to 2.27.0-17
git-web - update to 2.27.0-17
perl-Git - update to 2.27.0-17
gitk - update to 2.27.0-17
git-email - update to 2.27.0-17
git-gui - update to 2.27.0-17
git-debuginfo - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
perl-Git - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-p4 - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-doc - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-arch - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-credential-gnome-keyring - update to 2.35.3-150300.10.39.1
git-credential-gnome-keyring-debuginfo - update to 2.35.3-150300.10.39.1
git-credential-libsecret - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-credential-libsecret-debuginfo - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git - addressed in versions 2.38.4-1.81, 2.40.1-1
git - update to 2.39.4
git (Debian package) - update to 1:2.39.5-0+deb12u1
perl-Git - update to 2.43.5-1.0.1
gitweb - update to 2.43.5-1.0.1
gitk - update to 2.43.5-1.0.1
git-svn - update to 2.43.5-1.0.1
git-instaweb - update to 2.43.5-1.0.1
git-gui - update to 2.43.5-1.0.1
git-email - update to 2.43.5-1.0.1
perl-Git-SVN - update to 2.43.5-1.0.1
git-core-doc - update to 2.43.5-1.0.1
git-all - update to 2.43.5-1.0.1
git-subtree - update to 2.43.5-1.0.1
git - update to 2.43.5-1.0.1
git-core - update to 2.43.5-1.0.1
git-credential-libsecret - update to 2.43.5-1.0.1
git-daemon - update to 2.43.5-1.0.1
git - update to 2.45.1-1.fc40
OpenManage Network Integration (OMNI) - update to 3.7
Red Hat OpenShift Dev Spaces - addressed in versions 3.15.0, 3.16.0, 3.17.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.61, 4.12.65, 4.12.66, 4.13.45, 4.14.32, 4.14.33, 4.16.3, 4.16.15, 4.17.0
Storage Resource Manager - update to 5.0.1.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
OpenShift Logging - addressed in versions 5.6.21, 5.8.9
Oracle Solaris - update to 11.4 SRU 71
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
Autodesk Infraworks - addressed in versions 2022.1.10.363, 2023.1.5.251, 2024.1.4.152, 2025.02.86

External References

Related Security Bulletins