Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5m5g-r44m-96r4

Опубликовано: 17 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.8

Описание

An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes defined on the related Personal Access Token. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in version 3.13.1, 3.12.6, 3.11.12, 3.10.14, and 3.9.17.

An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes defined on the related Personal Access Token. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in version 3.13.1, 3.12.6, 3.11.12, 3.10.14, and 3.9.17.

EPSS

Процентиль: 51%
0.00279
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 5.8
nvd
больше 1 года назад

An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes defined on the related Personal Access Token. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in version 3.13.1, 3.12.6, 3.11.12, 3.10.14, and 3.9.17.

EPSS

Процентиль: 51%
0.00279
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-269