{
  "threat_severity" : "Important",
  "public_date" : "2024-05-14T00:00:00Z",
  "bugzilla" : {
    "description" : "git: Recursive clones RCE",
    "id" : "2280421",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2280421"
  },
  "cvss3" : {
    "cvss3_base_score" : "9.0",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-22",
  "details" : [ "Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is disabled in Git (e.g. via `git config --global core.symlinks false`), the described attack won't work. As always, it is best to avoid cloning repositories from untrusted sources.", "A vulnerability was found in Git. This vulnerability allows the malicious manipulation of repositories containing submodules, exploiting a bug that enables the writing of files into the .git/ directory instead of the submodule's intended worktree. This manipulation facilitates the execution of arbitrary code during the cloning process, bypassing user inspection and control." ],
  "statement" : "While the described bug in Git presents a significant security concern, it falls short of being categorized as Critical due to several factors. The exploit requires a specific set of conditions, such as repositories with submodules and the presence of symbolic link support. Additionally, successful exploitation relies on users cloning repositories from untrusted sources, limiting its scope compared to critical vulnerabilities that may be remotely exploitable or affect a broader range of use cases. However, the potential impact of remote code execution during cloning operations underscores the importance of promptly applying patches and exercising caution when interacting with Git repositories, emphasizing its significant severity within the realm of software security.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2024-06-25T00:00:00Z",
    "advisory" : "RHSA-2024:4084",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "git-0:2.43.5-1.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
    "release_date" : "2024-08-29T00:00:00Z",
    "advisory" : "RHSA-2024:6028",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.4",
    "package" : "git-0:2.27.0-5.el8_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Telecommunications Update Service",
    "release_date" : "2024-08-29T00:00:00Z",
    "advisory" : "RHSA-2024:6028",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.4",
    "package" : "git-0:2.27.0-5.el8_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions",
    "release_date" : "2024-08-29T00:00:00Z",
    "advisory" : "RHSA-2024:6028",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.4",
    "package" : "git-0:2.27.0-5.el8_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
    "release_date" : "2024-08-29T00:00:00Z",
    "advisory" : "RHSA-2024:6027",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.6",
    "package" : "git-0:2.31.8-3.el8_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
    "release_date" : "2024-08-29T00:00:00Z",
    "advisory" : "RHSA-2024:6027",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.6",
    "package" : "git-0:2.31.8-3.el8_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
    "release_date" : "2024-08-29T00:00:00Z",
    "advisory" : "RHSA-2024:6027",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.6",
    "package" : "git-0:2.31.8-3.el8_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Extended Update Support",
    "release_date" : "2024-07-16T00:00:00Z",
    "advisory" : "RHSA-2024:4579",
    "cpe" : "cpe:/a:redhat:rhel_eus:8.8",
    "package" : "git-0:2.39.5-1.el8_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2024-06-25T00:00:00Z",
    "advisory" : "RHSA-2024:4083",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "git-0:2.43.5-1.el9_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
    "release_date" : "2024-09-11T00:00:00Z",
    "advisory" : "RHSA-2024:6610",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.0",
    "package" : "git-0:2.31.1-6.el9_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Extended Update Support",
    "release_date" : "2024-07-08T00:00:00Z",
    "advisory" : "RHSA-2024:4368",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.2",
    "package" : "git-0:2.39.5-1.el9_2"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Affected",
    "package_name" : "git",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "git",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Will not fix",
    "package_name" : "git",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Fuse 7",
    "fix_state" : "Will not fix",
    "package_name" : "git",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7"
  }, {
    "product_name" : "Red Hat Software Collections",
    "fix_state" : "Out of support scope",
    "package_name" : "rh-git227-git",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:3"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2024-32002\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-32002\nhttps://github.com/git/git/security/advisories/GHSA-8h77-4q3w-gfgv" ],
  "name" : "CVE-2024-32002",
  "mitigation" : {
    "value" : "One preventative measure is to disable symbolic link support. This can be accomplished by running the command git config --global core.symlinks false. Another temporary option is to avoid using the --recurse-submodules setting with untrusted git repos.",
    "lang" : "en:us"
  },
  "csaw" : false
}