Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-3124

Опубликовано: 17 апр. 2025
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise have access to in the Security Overview in GitHub Advanced Security. The Security Overview was required to be filtered only using the archived: filter and all other access controls were functioning normally. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.17 and was fixed in versions 3.13.14, 3.14.11, 3.15.6, and 3.16.2.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
Версия до 3.13.14 (исключая)
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
Версия от 3.14.0 (включая) до 3.14.11 (исключая)
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
Версия от 3.15.0 (включая) до 3.15.6 (исключая)
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
Версия от 3.16.0 (включая) до 3.16.2 (исключая)

EPSS

Процентиль: 20%
0.00064
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
github
10 месяцев назад

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise have access to in the Security Overview in GitHub Advanced Security. The Security Overview was required to be filtered only using the `archived:` filter and all other access controls were functioning normally. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.17 and was fixed in versions 3.13.14, 3.14.11, 3.15.6, and 3.16.2.

CVSS3: 5.3
fstec
10 месяцев назад

Уязвимость корпоративной версии платформы GitHub Enterprise Server, связанная с отсутствием процедуры авторизации, позволяющая нарушителю видеть имена частных репозиториев

EPSS

Процентиль: 20%
0.00064
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862