Remote Code Execution while cloning special-crafted local repositories
Package
git
Affected versions
v2.45.0 v2.44.0 <=v2.43.3 <=v2.42.1 v2.41.0 <=v2.40.1 <=v2.39.3
Patched versions
v2.45.1 v2.44.1 v2.43.4 v2.42.2 v2.41.1 v2.40.2 v2.39.4
Impact
An attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation.
Patches
The problem has been patched in the versions published on Tuesday, May 14th, 2024.
Workarounds
Avoid cloning repositories from untrusted sources.
References
git clone