Lucene search

K
hackeroneInspector-ambitiousH1:2216036
HistoryOct 19, 2023 - 2:32 p.m.

GitHub: RC Between GitHub's Repo Transfer REST API and updateTeamsRepository GraphQL Mutation Results in Covert and Persistent Admin Access Retention

2023-10-1914:32:53
inspector-ambitious
hackerone.com
$4000
11
github
race condition
admin access
repository transfer
rest api
graphql mutation
vulnerability
github enterprise server
bug bounty

6.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.9%

A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphQL mutation to alter repository permissions during the transfer. This vulnerability affected GitHub Enterprise Server version 3.8.0 and above and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.

6.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.9%

Related for H1:2216036