Логотип exploitDog
bind:CVE-2023-51381
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-51381

Количество 2

Количество 2

nvd логотип

CVE-2023-51381

около 2 лет назад

Rejected reason: This CVE ID has been rejected or withdrawn by GitHub.

EPSS: Низкий
github логотип

GHSA-f487-r7gx-mx7f

около 2 лет назад

Cross-site Scripting in the tag name pattern field in the tag protections UI in GitHub Enterprise Server 3.8.12, 3.9.7, 3.10.4, 3.11.2 allows a malicious website that requires user interaction and social engineering to make changes to a user account via CSP bypass with created CSRF tokens. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in all versions of 3.11.3, 3.10.5, 3.9.8, and 3.8.13. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 3.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-51381

Rejected reason: This CVE ID has been rejected or withdrawn by GitHub.

около 2 лет назад
github логотип
GHSA-f487-r7gx-mx7f

Cross-site Scripting in the tag name pattern field in the tag protections UI in GitHub Enterprise Server 3.8.12, 3.9.7, 3.10.4, 3.11.2 allows a malicious website that requires user interaction and social engineering to make changes to a user account via CSP bypass with created CSRF tokens. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in all versions of 3.11.3, 3.10.5, 3.9.8, and 3.8.13. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 3.7
около 2 лет назад

Уязвимостей на страницу