Rapid7 Vulnerability & Exploit Database

Oracle Linux: CVE-2024-32020: ELSA-2024-4083: git security update (IMPORTANT) (Multiple Advisories)

Free InsightVM Trial No Credit Card Necessary
2024 Attack Intel Report Latest research by Rapid7 Labs
Back to Search

Oracle Linux: CVE-2024-32020: ELSA-2024-4083: git security update (IMPORTANT) (Multiple Advisories)

Severity
2
CVSS
(AV:L/AC:H/Au:S/C:N/I:P/A:P)
Published
05/14/2024
Created
06/27/2024
Added
06/25/2024
Modified
11/28/2024

Description

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, local clones may end up hardlinking files into the target repository's object database when source and target repository reside on the same disk. If the source repository is owned by a different user, then those hardlinked files may be rewritten at any point in time by the untrusted user. Cloning local repositories will cause Git to either copy or hardlink files of the source repository into the target repository. This significantly speeds up such local clones compared to doing a "proper" clone and saves both disk space and compute time. When cloning a repository located on the same disk that is owned by a different user than the current user we also end up creating such hardlinks. These files will continue to be owned and controlled by the potentially-untrusted user and can be rewritten by them at will in the future. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. A vulnerability was found in Git. This flaw allows an unauthenticated attacker to place a specialized repository on their target's local system. For performance reasons, Git uses hardlinks when cloning a repository located on the same disk. However, if the repo being cloned is owned by a different user, this can introduce a security risk. At any time in the future, the original repo owner could rewrite the hardlinked files in the cloned user's repo.

Solution(s)

  • oracle-linux-upgrade-git
  • oracle-linux-upgrade-git-all
  • oracle-linux-upgrade-git-core
  • oracle-linux-upgrade-git-core-doc
  • oracle-linux-upgrade-git-credential-libsecret
  • oracle-linux-upgrade-git-daemon
  • oracle-linux-upgrade-git-email
  • oracle-linux-upgrade-git-gui
  • oracle-linux-upgrade-git-instaweb
  • oracle-linux-upgrade-gitk
  • oracle-linux-upgrade-git-subtree
  • oracle-linux-upgrade-git-svn
  • oracle-linux-upgrade-gitweb
  • oracle-linux-upgrade-perl-git
  • oracle-linux-upgrade-perl-git-svn

insightVM

Advanced vulnerability management analytics and reporting.
Key Features
  • Lightweight Endpoint Agent
  • Live Dashboards
  • Real Risk Prioritization
  • IT-Integrated Remediation Projects
  • Cloud, Virtual, and Container Assessment
  • Integrated Threat Feeds
  • Easy-to-Use RESTful API
  • Automation-Assisted Patching
  • Automated Containment
Free InsightVM Trial View All Features

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;