Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fwfp-h68w-2hcr

Опубликовано: 27 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.2
CVSS3: 8.2

Описание

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal content into request parameters, an attacker could bypass the intended request flow and redirect internal API calls, potentially accessing internal services and exposing sensitive credentials. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.16.20, 3.17.17, 3.18.11, 3.19.8, 3.20.4, and 3.21.1. This vulnerability was reported via the GitHub Bug Bounty program.

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal content into request parameters, an attacker could bypass the intended request flow and redirect internal API calls, potentially accessing internal services and exposing sensitive credentials. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.16.20, 3.17.17, 3.18.11, 3.19.8, 3.20.4, and 3.21.1. This vulnerability was reported via the GitHub Bug Bounty program.

EPSS

Процентиль: 93%
0.06605
Низкий

9.2 Critical

CVSS4

8.2 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.2
nvd
2 месяца назад

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal content into request parameters, an attacker could bypass the intended request flow and redirect internal API calls, potentially accessing internal services and exposing sensitive credentials. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.17, 3.18.11, 3.19.8, 3.20.4, and 3.21.2. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 7.5
fstec
2 месяца назад

Уязвимость конечной точки загрузки корпоративной версии платформы GitHub Enterprise Server, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 93%
0.06605
Низкий

9.2 Critical

CVSS4

8.2 High

CVSS3

Дефекты

CWE-918