Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fvw7-7rxq-453v

Опубликовано: 18 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise have access to in the Security Overview in GitHub Advanced Security. The Security Overview was required to be filtered only using the archived: filter and all other access controls were functioning normally. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.17 and was fixed in versions 3.13.14, 3.14.11, 3.15.6, and 3.16.2.

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise have access to in the Security Overview in GitHub Advanced Security. The Security Overview was required to be filtered only using the archived: filter and all other access controls were functioning normally. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.17 and was fixed in versions 3.13.14, 3.14.11, 3.15.6, and 3.16.2.

EPSS

Процентиль: 20%
0.00064
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
10 месяцев назад

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise have access to in the Security Overview in GitHub Advanced Security. The Security Overview was required to be filtered only using the `archived:` filter and all other access controls were functioning normally. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.17 and was fixed in versions 3.13.14, 3.14.11, 3.15.6, and 3.16.2.

CVSS3: 5.3
fstec
10 месяцев назад

Уязвимость корпоративной версии платформы GitHub Enterprise Server, связанная с отсутствием процедуры авторизации, позволяющая нарушителю видеть имена частных репозиториев

EPSS

Процентиль: 20%
0.00064
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-862