Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-43041.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-43041
Upstream
Published
2024-05-14T19:15:11Z
Modified
2026-04-01T05:14:58.303343Z
Summary
CVE-2024-32004 affecting package git for versions less than 2.45.2-1
Details

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid cloning repositories from untrusted sources.

References

Affected packages

Azure Linux:3 / git

Package

Name
git
Purl
pkg:rpm/azure-linux/git

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.45.2-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-43041.json"