Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-32002— Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution

Quick assessment

Affected
git git
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Microsoft Visual Studio是美国微软(Microsoft)公司的一款开发工具套件系列产品,也是一个基本完整的开发工具集,它包括了整个软件生命周期中所需要的大部分工具。 Microsoft Visual Studio存在安全漏洞的相关信息,请随时关注CNNVD或厂商公告。

CVSS 9.1 · Critical EPSS 29.23% · P98
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-32002

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
Source: CVE Program / CVE List V5
Vulnerability Description
Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is disabled in Git (e.g. via `git config --global core.symlinks false`), the described attack won't work. As always, it is best to avoid cloning repositories from untrusted sources.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5
Vulnerability Title
Microsoft Visual Studio 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Visual Studio是美国微软(Microsoft)公司的一款开发工具套件系列产品,也是一个基本完整的开发工具集,它包括了整个软件生命周期中所需要的大部分工具。 Microsoft Visual Studio存在安全漏洞的相关信息,请随时关注CNNVD或厂商公告。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
git git = 2.45.0 -

II. Public POCs for CVE-2024-32002

# POC Description Source Link Shenlong Link
1 None https://github.com/Disseminator/CVE-2024-32002 POC Details
2 A submodule for exploiting CVE-2024-32002 vulnerability. https://github.com/markuta/hooky POC Details
3 Exploit PoC for CVE-2024-32002 https://github.com/amalmurali47/git_rce POC Details
4 Hook for the PoC for exploiting CVE-2024-32002 https://github.com/amalmurali47/hook POC Details
5 local poc for CVE-2024-32002 https://github.com/M507/CVE-2024-32002 POC Details
6 CVE-2024-32002 RCE PoC https://github.com/safebuffer/CVE-2024-32002 POC Details
7 None https://github.com/10cks/CVE-2024-32002-POC POC Details
8 None https://github.com/10cks/CVE-2024-32002-hulk POC Details
9 None https://github.com/10cks/CVE-2024-32002-submod POC Details
10 None https://github.com/10cks/CVE-2024-32002-smash POC Details
11 None https://github.com/10cks/CVE-2024-32002-linux-hulk POC Details
12 None https://github.com/10cks/CVE-2024-32002-linux-submod POC Details
13 None https://github.com/10cks/CVE-2024-32002-linux-smash POC Details
14 None https://github.com/aitorcastel/poc_CVE-2024-32002 POC Details
15 None https://github.com/aitorcastel/poc_CVE-2024-32002_submodule POC Details
16 CVE-2024-32002-hook https://github.com/10cks/hook POC Details
17 None https://github.com/jweny/CVE-2024-32002_HOOK POC Details
18 None https://github.com/jweny/CVE-2024-32002_EXP POC Details
19 None https://github.com/CrackerCat/CVE-2024-32002_EXP POC Details
20 None https://github.com/KiranKumarK20/CVE-2024-32002 POC Details
21 None https://github.com/jerrydotlam/cve-2024-32002-1 POC Details
22 None https://github.com/jerrydotlam/cve-2024-32002-2 POC Details
23 None https://github.com/jerrydotlam/cve-2024-32002-3 POC Details
24 None https://github.com/1mxml/CVE-2024-32002-poc POC Details
25 CVE-2024-32002 hook POC https://github.com/Roronoawjd/hook POC Details
26 None https://github.com/JakobTheDev/cve-2024-32002-submodule-rce POC Details
27 None https://github.com/JakobTheDev/cve-2024-32002-poc-rce POC Details
28 CVE-2024-32002 POC https://github.com/Roronoawjd/git_rce POC Details
29 Este script demuestra cómo explotar la vulnerabilidad CVE-2024-32002 para obtener una reverse shell, proporcionando acceso remoto al sistema afectado. Úselo con precaución en entornos controlados y solo con fines educativos o de pruebas de seguridad. https://github.com/JJoosh/CVE-2024-32002-Reverse-Shell POC Details
30 None https://github.com/YuanlooSec/CVE-2024-32002-poc POC Details
AI-Generated POC Verified env Premium
Qwen3.6-35B-A3B · 10503 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2024-32002

请登录查看更多情报信息。

Patches & Fixes for CVE-2024-32002 (1)

Vendor Advisories for CVE-2024-32002 (1)

Mailing List Discussions for CVE-2024-32002 (3)

Other References for CVE-2024-32002 (2)

Same Patch Batch · git · 2024-05-14 · 5 CVEs total

CVE-2024-32004 8.2 HIGH Git vulnerable to Remote Code Execution while cloning special-crafted local repositories
CVE-2024-32465 7.4 HIGH Git's protections for cloning untrusted repositories can be bypassed
CVE-2024-32020 3.9 LOW Cloning local Git repository by untrusted user allows the untrusted user to modify objects
CVE-2024-32021 3.9 LOW Local Git clone may hardlink arbitrary user-readable files into the new repository's "obje

IV. Related Vulnerabilities

V. Comments for CVE-2024-32002

No comments yet


Leave a comment