Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q586-q77x-838f

Опубликовано: 23 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 6.2
CVSS3: 2.7

Описание

An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.

An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.

EPSS

Процентиль: 31%
0.00118
Низкий

6.2 Medium

CVSS4

2.7 Low

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 2.7
nvd
больше 1 года назад

An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.

EPSS

Процентиль: 31%
0.00118
Низкий

6.2 Medium

CVSS4

2.7 Low

CVSS3

Дефекты

CWE-269