Arbitrary file upload in Git - CVE-2024-32002
Published: May 15, 2024 / Updated: August 29, 2025
Vulnerability identifier: #VU89491
CSH Severity: High
CVSS v4 BT: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber]
CVE-ID: CVE-2024-32002
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload. A remote attacker can upload a malicious file and execute it on the server.
Affected software
Git
Migration Toolkit for Containers
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
Amazon Linux AMI
Oracle Linux
Debian Linux
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Slackware Linux
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Development Tools Module
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Oracle Solaris
Voice Gateway
Apple Xcode
Visual Studio
Git for Windows
OpenManage Network Integration (OMNI)
Storage Resource Manager
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
git (Ubuntu package)
swiftlint
git-email
git-gui
gitk
git-web
git-cvs
git-daemon-debuginfo
git-core-debuginfo
git-debugsource
git-svn
git-daemon
git-core
git
perl-Git
perl-Git-SVN
git-help
git-debuginfo
git (Red Hat package)
git-doc
git-p4
git-arch
git-credential-gnome-keyring
git-credential-gnome-keyring-debuginfo
git-credential-libsecret-debuginfo
git-credential-libsecret
git (Debian package)
git-subtree
git-all
git-core-doc
git-instaweb
gitweb
Juniper Junos Space
Red Hat OpenShift GitOps
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
OpenShift Logging
IBM Cloud Pak for Business Automation
Autodesk Infraworks
Dell EMC Storage Monitoring and Reporting (SMR)
Migration Toolkit for Containers
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
Amazon Linux AMI
Oracle Linux
Debian Linux
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Slackware Linux
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Development Tools Module
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Oracle Solaris
Voice Gateway
Apple Xcode
Visual Studio
Git for Windows
OpenManage Network Integration (OMNI)
Storage Resource Manager
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
git (Ubuntu package)
swiftlint
git-email
git-gui
gitk
git-web
git-cvs
git-daemon-debuginfo
git-core-debuginfo
git-debugsource
git-svn
git-daemon
git-core
git
perl-Git
perl-Git-SVN
git-help
git-debuginfo
git (Red Hat package)
git-doc
git-p4
git-arch
git-credential-gnome-keyring
git-credential-gnome-keyring-debuginfo
git-credential-libsecret-debuginfo
git-credential-libsecret
git (Debian package)
git-subtree
git-all
git-core-doc
git-instaweb
gitweb
Juniper Junos Space
Red Hat OpenShift GitOps
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
OpenShift Logging
IBM Cloud Pak for Business Automation
Autodesk Infraworks
Dell EMC Storage Monitoring and Reporting (SMR)
How to mitigate CVE-2024-32002
Install updates from vendor's website.
Git - addressed in versions 2.39.4, 2.40.2, 2.41.1, 2.42.2, 2.43.4, 2.44.1, 2.45.1
Voice Gateway - update to 1.0.8.12
Apple Xcode - update to 16.0
Git for Windows - addressed in versions 2.39.4.1, 2.43.4.1, 2.44.1.1, 2.45.1.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
Juniper Junos Space - update to 24.1R3
git (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:2.25.1-1ubuntu3.12, 1:2.25.1-1ubuntu3.13, 1:2.34.1-1ubuntu1.11, 1:2.40.1-1ubuntu1.1, 1:2.43.0-1ubuntu7.1
swiftlint - update to 0.57.1-1.fc42
Migration Toolkit for Containers - update to 1.8.4
Red Hat OpenShift GitOps - addressed in versions 1.11.6, 1.12.5, 1.13.1
IBM Cloud Pak for Multicloud Management - update to 2.3 FP11
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.7, 2.9.5, 2.10.4
git-email - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-gui - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
gitk - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-web - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-cvs - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-daemon-debuginfo - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-core-debuginfo - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-debugsource - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-svn - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-daemon - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-core - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
perl-Git - update to 2.27.0-17
git-web - update to 2.27.0-17
perl-Git-SVN - update to 2.27.0-17
git-help - update to 2.27.0-17
git-svn - update to 2.27.0-17
git-debuginfo - update to 2.27.0-17
git-daemon - update to 2.27.0-17
git-debugsource - update to 2.27.0-17
git - update to 2.27.0-17
gitk - update to 2.27.0-17
git-gui - update to 2.27.0-17
git-email - update to 2.27.0-17
git (Red Hat package) - addressed in versions 2.31.1-6.el9_0, 2.39.5-1.el8_8, 2.43.5-1.el8_10, 2.43.5-1.el9_4
perl-Git - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-debuginfo - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-doc - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-p4 - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-arch - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-credential-gnome-keyring - update to 2.35.3-150300.10.39.1
git-credential-gnome-keyring-debuginfo - update to 2.35.3-150300.10.39.1
git-credential-libsecret-debuginfo - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-credential-libsecret - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git - addressed in versions 2.38.4-1.81, 2.40.1-1
git - update to 2.39.4
git (Debian package) - update to 1:2.39.5-0+deb12u1
git-daemon - update to 2.43.5-1.0.1
git - update to 2.43.5-1.0.1
git-core - update to 2.43.5-1.0.1
git-credential-libsecret - update to 2.43.5-1.0.1
git-subtree - update to 2.43.5-1.0.1
git-all - update to 2.43.5-1.0.1
git-core-doc - update to 2.43.5-1.0.1
git-email - update to 2.43.5-1.0.1
git-gui - update to 2.43.5-1.0.1
git-instaweb - update to 2.43.5-1.0.1
git-svn - update to 2.43.5-1.0.1
gitk - update to 2.43.5-1.0.1
gitweb - update to 2.43.5-1.0.1
perl-Git - update to 2.43.5-1.0.1
perl-Git-SVN - update to 2.43.5-1.0.1
git - update to 2.45.1-1.fc40
OpenManage Network Integration (OMNI) - update to 3.7
Red Hat OpenShift Dev Spaces - addressed in versions 3.15.0, 3.16.0, 3.17.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.61, 4.12.65, 4.12.66, 4.13.45, 4.14.32, 4.14.33, 4.16.3, 4.16.15, 4.17.0
Storage Resource Manager - update to 5.0.1.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
OpenShift Logging - addressed in versions 5.6.21, 5.8.9
Oracle Solaris - update to 11.4 SRU 71
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
Autodesk Infraworks - addressed in versions 2022.1.10.363, 2023.1.5.251, 2024.1.4.152, 2025.02.86
Voice Gateway - update to 1.0.8.12
Apple Xcode - update to 16.0
Git for Windows - addressed in versions 2.39.4.1, 2.43.4.1, 2.44.1.1, 2.45.1.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
Juniper Junos Space - update to 24.1R3
git (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:2.25.1-1ubuntu3.12, 1:2.25.1-1ubuntu3.13, 1:2.34.1-1ubuntu1.11, 1:2.40.1-1ubuntu1.1, 1:2.43.0-1ubuntu7.1
swiftlint - update to 0.57.1-1.fc42
Migration Toolkit for Containers - update to 1.8.4
Red Hat OpenShift GitOps - addressed in versions 1.11.6, 1.12.5, 1.13.1
IBM Cloud Pak for Multicloud Management - update to 2.3 FP11
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.7, 2.9.5, 2.10.4
git-email - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-gui - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
gitk - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-web - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-cvs - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-daemon-debuginfo - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-core-debuginfo - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-debugsource - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-svn - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-daemon - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-core - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
perl-Git - update to 2.27.0-17
git-web - update to 2.27.0-17
perl-Git-SVN - update to 2.27.0-17
git-help - update to 2.27.0-17
git-svn - update to 2.27.0-17
git-debuginfo - update to 2.27.0-17
git-daemon - update to 2.27.0-17
git-debugsource - update to 2.27.0-17
git - update to 2.27.0-17
gitk - update to 2.27.0-17
git-gui - update to 2.27.0-17
git-email - update to 2.27.0-17
git (Red Hat package) - addressed in versions 2.31.1-6.el9_0, 2.39.5-1.el8_8, 2.43.5-1.el8_10, 2.43.5-1.el9_4
perl-Git - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-debuginfo - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-doc - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-p4 - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-arch - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-credential-gnome-keyring - update to 2.35.3-150300.10.39.1
git-credential-gnome-keyring-debuginfo - update to 2.35.3-150300.10.39.1
git-credential-libsecret-debuginfo - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-credential-libsecret - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git - addressed in versions 2.38.4-1.81, 2.40.1-1
git - update to 2.39.4
git (Debian package) - update to 1:2.39.5-0+deb12u1
git-daemon - update to 2.43.5-1.0.1
git - update to 2.43.5-1.0.1
git-core - update to 2.43.5-1.0.1
git-credential-libsecret - update to 2.43.5-1.0.1
git-subtree - update to 2.43.5-1.0.1
git-all - update to 2.43.5-1.0.1
git-core-doc - update to 2.43.5-1.0.1
git-email - update to 2.43.5-1.0.1
git-gui - update to 2.43.5-1.0.1
git-instaweb - update to 2.43.5-1.0.1
git-svn - update to 2.43.5-1.0.1
gitk - update to 2.43.5-1.0.1
gitweb - update to 2.43.5-1.0.1
perl-Git - update to 2.43.5-1.0.1
perl-Git-SVN - update to 2.43.5-1.0.1
git - update to 2.45.1-1.fc40
OpenManage Network Integration (OMNI) - update to 3.7
Red Hat OpenShift Dev Spaces - addressed in versions 3.15.0, 3.16.0, 3.17.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.61, 4.12.65, 4.12.66, 4.13.45, 4.14.32, 4.14.33, 4.16.3, 4.16.15, 4.17.0
Storage Resource Manager - update to 5.0.1.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
OpenShift Logging - addressed in versions 5.6.21, 5.8.9
Oracle Solaris - update to 11.4 SRU 71
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
Autodesk Infraworks - addressed in versions 2022.1.10.363, 2023.1.5.251, 2024.1.4.152, 2025.02.86
External References
Related Security Bulletins
- Microsoft Visual Studio update for Git
- Multiple vulnerabilities in Git
- Multiple vulnerabilities in Git for Windows
- Ubuntu update for git
- Amazon Linux AMI update for git
- SUSE update for git
- Fedora 40 update for git
- openEuler update for git
- Ubuntu update for git
- Red Hat Enterprise Linux 9 update for git
- Red Hat Enterprise Linux 8 update for git
- Slackware Linux update for git
- SUSE update for git
- SUSE update for git
- Oracle Solaris update for thrid-party components
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.11
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in OpenShift Logging 5.6
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.10
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Red Hat Enterprise Linux 8 update for git
- Multiple vulnerabilities in OpenShift Logging 5.8
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.13
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Amazon Linux AMI update for git
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.8
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Debian update for git
- Red Hat Enterprise Linux 9 update for git
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Ubuntu update for git
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Autodesk InfraWorks update for third-party components
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.9
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- Fedora 42 update for swiftlint
- Multiple vulnerabilities in Dell OpenManage Network Integration (OMNI)
- SUSE update for git
- Anolis OS update for git
- Multiple vulnerabilities in Apple Xcode
- Junos Space update for third-party components
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management