Lucene search

K
cve[email protected]CVE-2023-46646
HistoryDec 21, 2023 - 9:15 p.m.

CVE-2023-46646

2023-12-2121:15:08
CWE-639
web.nvd.nist.gov
15
github
enterprise server
cve-2023-46646
access control
unauthorized access

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

20.0%

Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the β€œGet a check run” API endpoint. This vulnerability did not allow unauthorized access to any repository content besides the name.Β This vulnerability affected GitHub Enterprise Server version 3.7.0 and above and was fixed in version 3.17.19, 3.8.12, 3.9.7 3.10.4, and 3.11.0.

Affected configurations

Vulners
NVD
Node
githubenterprise_serverRange3.7.0–3.7.18
OR
githubenterprise_serverRange3.8.0–3.8.11
OR
githubenterprise_serverRange3.9.0–3.9.6
OR
githubenterprise_serverRange3.10.0–3.10.3
VendorProductVersionCPE
githubenterprise_server*cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
githubenterprise_server*cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
githubenterprise_server*cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
githubenterprise_server*cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "affected",
    "product": "Enterprise Server",
    "vendor": "GitHub",
    "versions": [
      {
        "changes": [
          {
            "at": "3.7.19",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "3.7.18",
        "status": "affected",
        "version": "3.7.0",
        "versionType": "semver"
      },
      {
        "changes": [
          {
            "at": "3.8.12",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "3.8.11",
        "status": "affected",
        "version": "3.8.0",
        "versionType": "semver"
      },
      {
        "changes": [
          {
            "at": "3.9.7",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "3.9.6",
        "status": "affected",
        "version": "3.9.0",
        "versionType": "semver"
      },
      {
        "changes": [
          {
            "at": "3.10.4",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "3.10.3",
        "status": "affected",
        "version": "3.10.0",
        "versionType": "semver"
      },
      {
        "status": "unaffected",
        "version": "3.11.0"
      }
    ]
  }
]

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

20.0%

Related for CVE-2023-46646