Skip to main content

Incorrect Permission Assignment for Critical Resource

CVE-2024-32478

Severity Medium
Score 6.9/10

Summary

Git Credential Manager (GCM) is a secure Git credential helper. Prior to 2.5.0, the Debian package does not set root ownership on installed files. This allows user 1001 on a multi-user system can replace binary and gain other users' privileges. This vulnerability is fixed in 2.5.0.

  • HIGH
  • LOCAL
  • HIGH
  • CHANGED
  • REQUIRED
  • HIGH
  • HIGH
  • NONE

CWE-732 - Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

References

Advisory Timeline

  • Published