CVE-2024-52006: Newline confusion in credential helpers can lead to credential exfiltration in git

Published Jan 14, 2025
·
Updated

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. Git defines a line-based protocol that is used to exchange information between Git and Git credential helpers. Some ecosystems (most notably, .NET and node.js) interpret single Carriage Return characters as newlines, which renders the protections against CVE-2020-5260 incomplete for credential helpers that treat Carriage Returns in this way. This issue has been addressed in commit b01b9b8 which is included in release versions v2.48.1, v2.47.1, v2.46.3, v2.45.3, v2.44.3, v2.43.6, v2.42.4, v2.41.3, and v2.40.4. Users are advised to upgrade. Users unable to upgrade should avoid cloning from untrusted URLs, especially recursive clones.

Other sources

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. Git defines a line-based protocol that is used to exchange information between Git and Git credential helpers. Some ecosystems (most notably, .NET and node.js) interpret single Carriage Return characters as newlines, which renders the protections against CVE-2020-5260 incomplete for credential helpers that treat Carriage Returns in this way. This issue has been addressed in commit b01b9b8 which is included in release versions v2.48.1, v2.47.2, v2.46.3, v2.45.3, v2.44.3, v2.43.6, v2.42.4, v2.41.3, and v2.40.4. Users are advised to upgrade. Users unable to upgrade should avoid cloning from untrusted URLs, especially recursive clones.

NVD

Newline confusion in credential helpers can lead to credential exfiltration in git

Microsoft

Affected Software

16 affected componentsFixes available
debian/git<=1:2.30.2-1+deb11u2
1:2.30.2-1+deb11u41:2.39.5-0+deb12u21:2.47.2-0.11:2.49.0-1
Git Git<2.40.4
Git Git>=2.41.0<2.41.3
Git Git>=2.42.0<2.42.4
Git Git>=2.43.0<2.43.6
Git Git>=2.44.3<2.44.3
Git Git>=2.45.3<2.45.3
Git Git>=2.46.3<2.46.3
Git Git>=2.47.0<2.47.2
Git Git=2.48.0
Debian Debian Linux=11.0
Microsoft azl3 git 2.45.3-1
Microsoft cbl2 git 2.40.4-1
Microsoft azl3 git 2.45.2-1
Microsoft cbl2 git 2.39.4-1
Microsoft cbl2 git 2.39.4-1

Event History

Jan 14, 2025
CVE Published
via MITRE·06:39 PM
Data Sourced
via MITRE·06:39 PM
DescriptionWeakness
Data Sourced
via Red Hat·07:10 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
RemedyAffected Software
Jan 22, 2025
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
SeverityAffected Software
Updated
via Microsoft·08:00 AM
DescriptionSeverity
Feb 27, 2025
Data Sourced
via Ubuntu·07:03 PM
RemedyDescriptionSeverityAffected Software
Apr 18, 58390
Event
via NVD·11:21 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-52006?

CVE-2024-52006 has been classified as a high-severity vulnerability affecting Git.

2

How do I fix CVE-2024-52006?

To fix CVE-2024-52006, update Git to the latest version available in your distribution's package manager.

3

What versions of Git are affected by CVE-2024-52006?

CVE-2024-52006 affects Git versions up to and including 1:2.30.2-1+deb11u2, 1:2.30.2-1+deb11u3, 1:2.39.5-0+deb12u1, 1:2.45.2-1, and 1:2.47.1-1.

4

What type of vulnerability is CVE-2024-52006?

CVE-2024-52006 is a security vulnerability related to the Git credential helper protocol.

5

Is CVE-2024-52006 actively exploited in the wild?

As of the latest information, there are no known active exploits for CVE-2024-52006.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203