Products
GitHub Enterprise Server
- 3.10.17
- 3.11.15
- 3.12.9
- 3.13.4
- 3.14.1
Source
product-cna@github.com
Tags
CVE-2024-8263 details
Published : Sept. 23, 2024, 9:15 p.m.
Last Modified : Sept. 23, 2024, 9:15 p.m.
Last Modified : Sept. 23, 2024, 9:15 p.m.
Description
An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|---|---|
CWE-269 | Improper Privilege Management | The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. |
References
URL | Source |
---|---|
https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.17 | product-cna@github.com |
https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.15 | product-cna@github.com |
https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.9 | product-cna@github.com |
https://docs.github.com/en/enterprise-server@3.13/admin/release-notes#3.13.4 | product-cna@github.com |
https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.1 | product-cna@github.com |
This website uses the NVD API, but is not approved or certified by it.