5.3 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
0.001 Low
EPSS
Percentile
20.0%
Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the βGet a check runβ API endpoint. This vulnerability did not allow unauthorized access to any repository content besides the name.Β This vulnerability affected GitHub Enterprise Server version 3.7.0 and above and was fixed in version 3.17.19, 3.8.12, 3.9.7 3.10.4, and 3.11.0.
Vendor | Product | Version | CPE |
---|---|---|---|
github | enterprise_server | * | cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* |
github | enterprise_server | * | cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* |
github | enterprise_server | * | cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* |
github | enterprise_server | * | cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* |
[
{
"defaultStatus": "affected",
"product": "Enterprise Server",
"vendor": "GitHub",
"versions": [
{
"changes": [
{
"at": "3.7.19",
"status": "unaffected"
}
],
"lessThanOrEqual": "3.7.18",
"status": "affected",
"version": "3.7.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.8.12",
"status": "unaffected"
}
],
"lessThanOrEqual": "3.8.11",
"status": "affected",
"version": "3.8.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.9.7",
"status": "unaffected"
}
],
"lessThanOrEqual": "3.9.6",
"status": "affected",
"version": "3.9.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.10.4",
"status": "unaffected"
}
],
"lessThanOrEqual": "3.10.3",
"status": "affected",
"version": "3.10.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "3.11.0"
}
]
}
]