UNIX symbolic link following in Git - CVE-2024-32021

 

UNIX symbolic link following in Git - CVE-2024-32021

Published: June 7, 2024


Vulnerability identifier: #VU91287
CSH Severity: Medium
CVSS v4 BT: 3.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2024-32021
CWE-ID: CWE-61
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the original repository.

The vulnerability exists due to insecure symlink following issue. When cloning a local source repository that contains symlinks via the filesystem, Git may create hardlinks to arbitrary user-readable files on the same filesystem as the target repository in the objects/ directory.



Affected software

Git
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Amazon Linux AMI
Oracle Linux
Debian Linux
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Anolis OS
Slackware Linux
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Development Tools Module
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Oracle Solaris
Voice Gateway
Git for Windows
OpenManage Network Integration (OMNI)
Storage Resource Manager
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Juniper Junos Space
git (Ubuntu package)
swiftlint
git-gui
gitk
git-web
git-core-debuginfo
git-debugsource
git-cvs
git-email
git-daemon-debuginfo
git
git-core
git-daemon
git-svn
perl-Git
perl-Git-SVN
git-help
git-debuginfo
git-doc
git-p4
git-credential-libsecret-debuginfo
git-credential-libsecret
git-arch
git-credential-gnome-keyring
git-credential-gnome-keyring-debuginfo
git (Debian package)
git (Red Hat package)
git-subtree
git-all
git-core-doc
git-instaweb
gitweb
Red Hat OpenShift GitOps
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
OpenShift Logging
IBM Cloud Pak for Business Automation
Autodesk Infraworks
Dell EMC Storage Monitoring and Reporting (SMR)

How to mitigate CVE-2024-32021

Install updates from vendor's website.

Git - addressed in versions 2.39.5, 2.40.3, 2.41.2, 2.42.3, 2.43.5, 2.44.2, 2.45.2
Voice Gateway - update to 1.0.8.12
Git for Windows - addressed in versions 2.39.4.1, 2.43.4.1, 2.44.1.1, 2.45.1.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
Juniper Junos Space - update to 24.1R3
git (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:2.25.1-1ubuntu3.12, 1:2.34.1-1ubuntu1.11, 1:2.40.1-1ubuntu1.1, 1:2.43.0-1ubuntu7.1
swiftlint - update to 0.57.1-1.fc42
Migration Toolkit for Containers - update to 1.8.4
Red Hat OpenShift GitOps - addressed in versions 1.11.6, 1.12.5, 1.13.1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.7, 2.9.5, 2.10.4
git-gui - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
gitk - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-web - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-core-debuginfo - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-debugsource - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-cvs - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-email - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-daemon-debuginfo - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-core - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-daemon - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-svn - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-gui - update to 2.27.0-17
gitk - update to 2.27.0-17
perl-Git - update to 2.27.0-17
git-web - update to 2.27.0-17
perl-Git-SVN - update to 2.27.0-17
git-help - update to 2.27.0-17
git-svn - update to 2.27.0-17
git-debuginfo - update to 2.27.0-17
git-daemon - update to 2.27.0-17
git-debugsource - update to 2.27.0-17
git - update to 2.27.0-17
git-email - update to 2.27.0-17
perl-Git - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-debuginfo - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-doc - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-p4 - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-credential-libsecret-debuginfo - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-credential-libsecret - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-arch - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-credential-gnome-keyring - update to 2.35.3-150300.10.39.1
git-credential-gnome-keyring-debuginfo - update to 2.35.3-150300.10.39.1
git - addressed in versions 2.38.4-1.81, 2.40.1-1
git - update to 2.39.4
git (Debian package) - update to 1:2.39.5-0+deb12u1
git (Red Hat package) - addressed in versions 2.43.5-1.el8_10, 2.43.5-1.el9_4
git - update to 2.43.5-1.0.1
git-core - update to 2.43.5-1.0.1
git-credential-libsecret - update to 2.43.5-1.0.1
git-daemon - update to 2.43.5-1.0.1
git-subtree - update to 2.43.5-1.0.1
git-all - update to 2.43.5-1.0.1
git-core-doc - update to 2.43.5-1.0.1
git-email - update to 2.43.5-1.0.1
git-gui - update to 2.43.5-1.0.1
git-instaweb - update to 2.43.5-1.0.1
git-svn - update to 2.43.5-1.0.1
gitk - update to 2.43.5-1.0.1
gitweb - update to 2.43.5-1.0.1
perl-Git - update to 2.43.5-1.0.1
perl-Git-SVN - update to 2.43.5-1.0.1
git - update to 2.45.1-1.fc40
OpenManage Network Integration (OMNI) - update to 3.7
Red Hat OpenShift Dev Spaces - addressed in versions 3.15.0, 3.16.0, 3.17.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.61, 4.13.45, 4.14.32, 4.14.33, 4.16.3, 4.16.15, 4.17.0
Storage Resource Manager - update to 5.0.1.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
OpenShift Logging - addressed in versions 5.6.21, 5.8.9
Oracle Solaris - update to 11.4 SRU 71
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
Autodesk Infraworks - addressed in versions 2022.1.10.363, 2023.1.5.251, 2024.1.4.152, 2025.02.86

External References

Related Security Bulletins