TCP: Git Git Source Code Management clone_submodule Link Following

This signature detects attempts to exploit a known vulnerability against Git Source Code Management clone_submodule. A successful attack can lead to arbitrary code execution.

Extended Description

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is disabled in Git (e.g. via `git config --global core.symlinks false`), the described attack won't work. As always, it is best to avoid cloning repositories from untrusted sources.

Affected Products

Git git

References

CVE: CVE-2024-32002

Short Name
TCP:GIT-SRC-SM-LNK-FWLG
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
TCP
Keywords
CVE-2024-32002 Code Following Git Link Management Source clone_submodule
Release Date
07/09/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3721
Port
TCP/9418
False Positive
Unknown
Vendors

Git

Found a potential security threat?