Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7vvx-67x5-5jw2

Опубликовано: 14 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a scoped user-to-server token to escalate to full admin/owner privileges. An attacker would require an account with admin access to install a malicious GitHub App. This vulnerability was fixed in versions 3.3.17, 3.4.12, 3.5.9, and 3.6.5. This vulnerability was reported via the GitHub Bug Bounty program.

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a scoped user-to-server token to escalate to full admin/owner privileges. An attacker would require an account with admin access to install a malicious GitHub App. This vulnerability was fixed in versions 3.3.17, 3.4.12, 3.5.9, and 3.6.5. This vulnerability was reported via the GitHub Bug Bounty program.

EPSS

Процентиль: 75%
0.00869
Низкий

7.2 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 7.2
nvd
около 3 лет назад

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a scoped user-to-server token to escalate to full admin/owner privileges. An attacker would require an account with admin access to install a malicious GitHub App. This vulnerability was fixed in versions 3.3.17, 3.4.12, 3.5.9, and 3.6.5. This vulnerability was reported via the GitHub Bug Bounty program.

EPSS

Процентиль: 75%
0.00869
Низкий

7.2 High

CVSS3

Дефекты

CWE-863