CVE-2024-8770

Sept. 23, 2024, 9:15 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

GitHub Enterprise Server

  • 3.10.17
  • 3.11.15
  • 3.12.9
  • 3.13.4
  • 3.14.1

Source

product-cna@github.com

Tags

CVE-2024-8770 details

Published : Sept. 23, 2024, 9:15 p.m.
Last Modified : Sept. 23, 2024, 9:15 p.m.

Description

A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via social engineering. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
This website uses the NVD API, but is not approved or certified by it.