Products
GitHub Enterprise Server
- 3.10.17
- 3.11.15
- 3.12.9
- 3.13.4
- 3.14.1
Source
product-cna@github.com
Tags
CVE-2024-8770 details
Published : Sept. 23, 2024, 9:15 p.m.
Last Modified : Sept. 23, 2024, 9:15 p.m.
Last Modified : Sept. 23, 2024, 9:15 p.m.
Description
A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via social engineering. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|---|---|
CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |
References
URL | Source |
---|---|
https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.17 | product-cna@github.com |
https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.15 | product-cna@github.com |
https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.9 | product-cna@github.com |
https://docs.github.com/en/enterprise-server@3.13/admin/release-notes#3.13.4 | product-cna@github.com |
https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.1 | product-cna@github.com |
This website uses the NVD API, but is not approved or certified by it.