Proof-of-Concept Exploit Released for Critical Git Vulnerability CVE-2024-32002
Recursive clones on case-insensitive file systems that support symbolic links are susceptible to RCE
Summary
Recursive clones on case-insensitive file systems that support symbolic links are susceptible to RCE
Threat details
Introduction
A critical vulnerability known as CVE-2024-32002 has been discovered in Git, a distributed version control system often used for source code management by programmers and software developers.
This remote code execution (RCE) vulnerability has a CVSSv3 score of 9.0 and could be exploited by an attacker who could draft submodules in a particular way that can lead to writing files not into the submodule's worktree but into a .git/ directory. This situation could allow for writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed.
Proof-of-concept exploit code released for CVE-2024-32002
Proof-of-concept exploit code was published for this vulnerability.
Remediation advice
Affected organisations should review the git security advisory GHSA-8h77-4q3w-gfgv and apply any necessary updates or mitigation.
Definitive source of threat updates
Last edited: 21 May 2024 4:07 pm