GitHub Product Security Update Advisory (CVE-2024-52005)

Overview

We have released security updates to fix vulnerabilities in GitHub products. Users of affected products are advised to update to the latest version.

 

Affected Products

CVE-2024-52005

Git for Windows versions: 2.48.1 or below, 2.47.1 or below, 2.46.3 or below, 2.45.3 or below, 2.44.3 or below, 2.43.6 or below, 2.42.4 or below, 2.41.3 or below, 2.40.4 or below

 

 

Resolved Vulnerabilities

Remote message manipulation vulnerability via ANSI escape sequence (CVE-2024-52005)

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-52005

Git for Windows version: 2.47.1(2)

 

References

[1] The sideband payload is passed unfiltered to the terminal
https://github.com/git/git/security/advisories/GHSA-7jjc-gg6m-3329