CVE-2024-32002

CRITICAL

Git <2.45.1-2.39.4 - Code Injection

Title source: llm

Description

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is disabled in Git (e.g. via `git config --global core.symlinks false`), the described attack won't work. As always, it is best to avoid cloning repositories from untrusted sources.

Exploits (71)

nomisec WORKING POC 531 stars
by amalmurali47 · poc
https://github.com/amalmurali47/git_rce
nomisec WORKING POC 108 stars
by safebuffer · poc
https://github.com/safebuffer/CVE-2024-32002
nomisec SUSPICIOUS 16 stars
by amalmurali47 · poc
https://github.com/amalmurali47/hook
nomisec WORKING POC 9 stars
by M507 · poc
https://github.com/M507/CVE-2024-32002
nomisec WORKING POC 6 stars
by YukaFake · poc
https://github.com/YukaFake/CVE-2024-32002-Reverse-Shell
nomisec SUSPICIOUS 3 stars
by jweny · poc
https://github.com/jweny/CVE-2024-32002_EXP
nomisec NO CODE 3 stars
by jweny · poc
https://github.com/jweny/CVE-2024-32002_HOOK
nomisec WORKING POC 2 stars
by markuta · poc
https://github.com/markuta/CVE-2024-32002
nomisec WORKING POC 2 stars
by bfengj · poc
https://github.com/bfengj/CVE-2024-32002-Exploit
nomisec WORKING POC 2 stars
by 10cks · poc
https://github.com/10cks/CVE-2024-32002-EXP
nomisec WORKING POC 2 stars
by BasyacatX · poc
https://github.com/BasyacatX/CVE-2024-32002-PoC_Chinese
nomisec WORKING POC 2 stars
by NishanthAnand21 · poc
https://github.com/NishanthAnand21/CVE-2024-32002-PoC
nomisec NO CODE 1 stars
by 10cks · poc
https://github.com/10cks/hook
nomisec NO CODE 1 stars
by fadhilthomas · poc
https://github.com/fadhilthomas/poc-cve-2024-32002
nomisec NO CODE 1 stars
by CrackerCat · poc
https://github.com/CrackerCat/CVE-2024-32002_EXP
nomisec WORKING POC 1 stars
by grecosamuel · poc
https://github.com/grecosamuel/CVE-2024-32002
nomisec WORKING POC 1 stars
by BohemianHacks · poc
https://github.com/BohemianHacks/CVE-2024-32002-poc
nomisec WORKING POC 1 stars
by JakobTheDev · poc
https://github.com/JakobTheDev/cve-2024-32002-poc-rce
nomisec STUB 1 stars
by Goplush · poc
https://github.com/Goplush/CVE-2024-32002-git-rce
nomisec TROJAN 1 stars
by th4s1s · poc
https://github.com/th4s1s/CVE-2024-32002-PoC
nomisec STUB
by vincepsh · poc
https://github.com/vincepsh/CVE-2024-32002-hook
nomisec STUB
by vincepsh · poc
https://github.com/vincepsh/CVE-2024-32002
nomisec STUB
by sysonlai · poc
https://github.com/sysonlai/CVE-2024-32002-hook
nomisec NO CODE
by 10cks · poc
https://github.com/10cks/CVE-2024-32002-linux-submod
nomisec WORKING POC
by JakobTheDev · poc
https://github.com/JakobTheDev/cve-2024-32002-poc-aw
nomisec STUB
by WOOOOONG · poc
https://github.com/WOOOOONG/CVE-2024-32002
nomisec STUB
by WOOOOONG · poc
https://github.com/WOOOOONG/hook
nomisec NO CODE
by charlesgargasson · poc
https://github.com/charlesgargasson/CVE-2024-32002
nomisec NO CODE
by Dre4m017 · poc
https://github.com/Dre4m017/fuzzy
nomisec NO CODE
by 10cks · poc
https://github.com/10cks/CVE-2024-32002-linux-hulk
nomisec NO CODE
by tobelight · poc
https://github.com/tobelight/cve_2024_32002
nomisec STUB
by Roronoawjd · poc
https://github.com/Roronoawjd/hook
nomisec SUSPICIOUS
by YukaFake · poc
https://github.com/YukaFake/CVE-2024-32002
nomisec STUB
by JakobTheDev · poc
https://github.com/JakobTheDev/cve-2024-32002-submodule-aw
nomisec NO CODE
by aitorcastel · poc
https://github.com/aitorcastel/poc_CVE-2024-32002_submodule
nomisec SUSPICIOUS
by SpycioKon · poc
https://github.com/SpycioKon/CVE-2024-32002
nomisec NO CODE
by aitorcastel · poc
https://github.com/aitorcastel/poc_CVE-2024-32002
nomisec NO CODE
by Julian-gmz · poc
https://github.com/Julian-gmz/hook_CVE-2024-32002
github WORKING POC
by wnaspy · shellpoc
https://github.com/wnaspy/CVE-POC-WEAPON/tree/main/tCVE-2024-32002.sh
nomisec WORKING POC
by markuta · poc
https://github.com/markuta/hooky
nomisec WORKING POC
by JakobTheDev · poc
https://github.com/JakobTheDev/cve-2024-32002-submodule-rce
nomisec WORKING POC
by Roronoawjd · poc
https://github.com/Roronoawjd/git_rce
nomisec WORKING POC
by 431m · poc
https://github.com/431m/rcetest
nomisec WORKING POC
by AD-Appledog · poc
https://github.com/AD-Appledog/CVE-2024-32002
nomisec SUSPICIOUS
by AD-Appledog · poc
https://github.com/AD-Appledog/wakuwaku
nomisec WORKING POC
by daemon-reconfig · poc
https://github.com/daemon-reconfig/CVE-2024-32002
nomisec WORKING POC
by FlojBoj · poc
https://github.com/FlojBoj/CVE-2024-32002
nomisec WORKING POC
by chrisWalker11 · poc
https://github.com/chrisWalker11/running-CVE-2024-32002-locally-for-tesing
nomisec WORKING POC
by sanan2004 · poc
https://github.com/sanan2004/CVE-2024-32002
nomisec WORKING POC
by ashutosh0408 · poc
https://github.com/ashutosh0408/CVE-2024-32002
nomisec WORKING POC
by ashutosh0408 · poc
https://github.com/ashutosh0408/Cve-2024-32002-poc
nomisec WORKING POC
by JoaoLeonello · poc
https://github.com/JoaoLeonello/cve-2024-32002-poc
nomisec SUSPICIOUS
by Masamuneee · poc
https://github.com/Masamuneee/CVE-2024-32002-POC
nomisec NO CODE
by 10cks · poc
https://github.com/10cks/CVE-2024-32002-submod
nomisec STUB
by srakkk · poc
https://github.com/srakkk/cve-2024-32002-demo
nomisec NO CODE
by 10cks · poc
https://github.com/10cks/CVE-2024-32002-hulk
nomisec STUB
by 10cks · poc
https://github.com/10cks/CVE-2024-32002-POC
nomisec WORKING POC
by blackninja23 · poc
https://github.com/blackninja23/CVE-2024-32002
nomisec STUB
by DayDayDayDreaming · poc
https://github.com/DayDayDayDreaming/backup-exec-hook
nomisec STUB
by srakkk · poc
https://github.com/srakkk/cve-2024-32002-hook
nomisec STUB
by DayDayDayDreaming · poc
https://github.com/DayDayDayDreaming/backup-exec-cve-32002
github WRITEUP
by bonnettheo · poc
https://github.com/bonnettheo/CVE-2024-32002
nomisec NO CODE
by bfengj · poc
https://github.com/bfengj/CVE-2024-32002-hook
nomisec NO CODE
by TSY244 · poc
https://github.com/TSY244/CVE-2024-32002-git-rce-father-poc
nomisec NO CODE
by TSY244 · poc
https://github.com/TSY244/CVE-2024-32002-git-rce
nomisec NO CODE
by fadhilthomas · poc
https://github.com/fadhilthomas/hook
nomisec STUB
by 1mxml · poc
https://github.com/1mxml/CVE-2024-32002-poc
nomisec STUB
by Masamuneee · poc
https://github.com/Masamuneee/hook

Scores

CVSS v3 9.0
EPSS 0.8038
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Classification

CWE
CWE-22 CWE-434 CWE-59
Status published

Affected Products (4)

git/git < 2.39.4
git/git
git/git
git/git

Timeline

Published May 14, 2024
Tracked Since Feb 18, 2026