CVE-2024-32002

9.0 CRITICAL
Published: May 14, 2024 Modified: November 04, 2025

Description

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is disabled in Git (e.g. via `git config --global core.symlinks false`), the described attack won't work. As always, it is best to avoid cloning repositories from untrusted sources.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.openwall.com/lists/oss-security/2024/05/14/2
Source: security-advisories@github.com
https://git-scm.com/docs/git-config#Documentation/git-config.txt-coresymlinks
Source: security-advisories@github.com
Not Applicable
https://github.com/git/git/security/advisories/GHSA-8h77-4q3w-gfgv
Source: security-advisories@github.com
Third Party Advisory
http://www.openwall.com/lists/oss-security/2024/05/14/2
Source: af854a3a-2127-422b-91ae-364da2661108
https://git-scm.com/docs/git-config#Documentation/git-config.txt-coresymlinks
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
https://github.com/git/git/commit/97065761333fd62db1912d81b489db938d8c991d
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
https://github.com/git/git/security/advisories/GHSA-8h77-4q3w-gfgv
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

15 reference(s) from NVD

Quick Stats

CVSS v3 Score
9.0 / 10.0
EPSS (Exploit Probability)
79.6%
99th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

git