V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2024-52005
ANC
HighConfirmedExploit available

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported…

CVSS
7.5
High
EPSS
0.00
p37
Published
2024-01-01
Updated
2024-01-01
Description

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

Tags · CWE
Pre-auth
CWE-116
CAPEC-73
CAPEC-81
CAPEC-85
CAPEC-104
Affected products
Git ≤ 2.40.4Git 2.41.0–2.41.3Git 2.42.0–2.42.4Git 2.43.0–2.43.6Git 2.44.0–2.44.3Git 2.45.0–2.45.3Git 2.46.0–2.46.3Git 2.47.0–2.47.1Git 2.48.0–2.48.1
CVSS vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Timeline
2024-01-01
Published
2024-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Attack Requirements
AT: N
None
Privileges Required
PR: N
None (N)
User Interaction
UI: A
Active
Vulnerable System Confidentiality
VC: H
High (H)
Vulnerable System Integrity
VI: H
High (H)
Vulnerable System Availability
VA: H
High (H)
Subsequent System Confidentiality
SC: N
None (N)
Subsequent System Integrity
SI: N
None (N)
Subsequent System Availability
SA: N
None (N)
Exploit Code Maturity
E: X
Not Defined
Confidentiality Requirement
CR: X
Not Defined
Integrity Requirement
IR: X
Not Defined
Availability Requirement
AR: X
Not Defined
Modified Attack Vector
MAV: X
Not Defined
Modified Attack Complexity
MAC: X
Not Defined
Modified Attack Requirements
MAT: X
Not Defined
Modified Privileges Required
MPR: X
Not Defined
Modified User Interaction
MUI: X
Not Defined
Modified Vulnerable System Confidentiality
MVC: X
Not Defined
Modified Vulnerable System Integrity
MVI: X
Not Defined
Modified Vulnerable System Availability
MVA: X
Not Defined
Modified Subsequent System Confidentiality
MSC: X
Not Defined
Modified Subsequent System Integrity
MSI: X
Not Defined
Modified Subsequent System Availability
MSA: X
Not Defined
s
S: X
X
au
AU: X
X
r
R: X
X
v
V: X
X
re
RE: X
X
u
U: X
X
Exploit indicators
EPSS
0.005 · p37
Known exploited (KEV)
No
Known exploits — Сканер-ВС
CVE-2024-52005
github-poc · https://github.com/andrewd-cg/cve-2024-52005-poc
Enterprise
Affected products
ProductVendorStatus
Tracked
gitTracked
gitTracked
gitTracked
gitTracked
gitTracked
gitTracked
gitTracked
git*Tracked
Source databases
ANC
DEB
CVE
UBU
Related vulnerabilities