Skip to main content

Proof-of-Concept Exploit Released for Critical Git Vulnerability CVE-2024-32002

Recursive clones on case-insensitive file systems that support symbolic links are susceptible to RCE

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Recursive clones on case-insensitive file systems that support symbolic links are susceptible to RCE


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

A critical vulnerability known as CVE-2024-32002 has been discovered in Git, a distributed version control system often used for source code management by programmers and software developers.

This remote code execution (RCE) vulnerability has a CVSSv3 score of 9.0 and could be exploited by an attacker who could draft submodules in a particular way that can lead to writing files not into the submodule's worktree but into a .git/ directory. This situation could allow for writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed.

Proof-of-concept exploit code released for CVE-2024-32002

Proof-of-concept exploit code was published for this vulnerability.


Remediation advice

Affected organisations should review the git security advisory GHSA-8h77-4q3w-gfgv and apply any necessary updates or mitigation.



Last edited: 21 May 2024 4:07 pm