CVE-2024-32021 is a high-severity vulnerability in Git that allows an attacker to create hardlinks to arbitrary user-readable files when cloning a local repository containing symlinks. This affects Git versions prior to 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4 across various distributions including Debian and Fedora. The vulnerability has a CVSS score of 7.1 (High), indicating a local attack vector with low complexity, requiring user interaction, and leading to high confidentiality and integrity impacts. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.39.4CPE matchmatch criteria | cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* | ||
>= 2.40.0, < 2.40.2CPE matchmatch criteria | cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* | ||
>= 2.42.0, < 2.42.2CPE matchmatch criteria | cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* | ||
>= 2.43.0, < 2.43.4CPE matchmatch criteria | cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* | ||
2.41.0CPE matchmatch criteria | cpe:2.3:a:git-scm:git:2.41.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2024-32021
Dec 10, 2024CVE-2024-32021
Nov 12, 2024CVE-2024-32021
Oct 8, 2024Local Git clone may hardlink arbitrary user-readable files into the new repository's "objects/" directory
May 14, 2024git: symlink bypass
May 14, 2024