CVE-2024-32478
Status: DeferredMedium (6.9)—
Git Credential Manager (GCM) is a secure Git credential helper. Prior to 2.5.0, the Debian package does not set root ownership on installed files. This allows user 1001 on a multi-user system can replace binary and gain other users' privileges. This vulnerability is fixed in 2.5.0.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N
- Base score: 6.9
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.19%
- Percentile among all scored CVEs: 8
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-732
References
- https://github.com/git-ecosystem/git-credential-manager/commit/d9ac33c5b1478383672b4425f5ecf875a62efba9
- https://github.com/git-ecosystem/git-credential-manager/security/advisories/GHSA-3c3g-h9rx-f7vq
- https://github.com/git-ecosystem/git-credential-manager/commit/d9ac33c5b1478383672b4425f5ecf875a62efba9
- https://github.com/git-ecosystem/git-credential-manager/security/advisories/GHSA-3c3g-h9rx-f7vq
Raw JSON (NVD)
Show
{
"id": "CVE-2024-32478",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-32478",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-07-26T15:03:15.465162Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.9,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.8,
"exploitabilityScore": 0.6
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "git-ecosystem",
"product": "git-credential-manager",
"versions": [
{
"status": "affected",
"version": "< 2.5.0"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:git-ecosystem:git-credential-manager:*:*:*:*:*:*:*:*"
],
"vendor": "git-ecosystem",
"product": "git-credential-manager",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.5.0",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-04-19T15:15:50.783",
"references": [
{
"url": "https://github.com/git-ecosystem/git-credential-manager/commit/d9ac33c5b1478383672b4425f5ecf875a62efba9",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/git-ecosystem/git-credential-manager/security/advisories/GHSA-3c3g-h9rx-f7vq",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/git-ecosystem/git-credential-manager/commit/d9ac33c5b1478383672b4425f5ecf875a62efba9",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/git-ecosystem/git-credential-manager/security/advisories/GHSA-3c3g-h9rx-f7vq",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-732"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Git Credential Manager (GCM) is a secure Git credential helper. Prior to 2.5.0, the Debian package does not set root ownership on installed files. This allows user 1001 on a multi-user system can replace binary and gain other users' privileges. This vulnerability is fixed in 2.5.0.\n"
},
{
"lang": "es",
"value": "Git Credential Manager (GCM) es un asistente seguro de credenciales Git. Antes de 2.5.0, el paquete Debian no establece la propiedad raíz de los archivos instalados. Esto permite que el usuario 1001 en un sistema multiusuario pueda reemplazar el binario y obtener los privilegios de otros usuarios. Esta vulnerabilidad se solucionó en 2.5.0."
}
],
"lastModified": "2026-06-17T07:29:42.380",
"sourceIdentifier": "security-advisories@github.com"
}