PT-2023-14887 · Github · Github Enterprise Server
Anthony Bouvet
·
Publicado
2023-03-07
·
Atualizado
2023-03-14
·
CVE-2022-46257
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GitHub Enterprise Server versions prior to 3.7
GitHub Enterprise Server versions 3.3 through 3.3.16
GitHub Enterprise Server versions 3.4 through 3.4.11
GitHub Enterprise Server versions 3.5 through 3.5.8
GitHub Enterprise Server versions 3.6 through 3.6.4
Description
An information disclosure issue was identified in GitHub Enterprise Server, allowing private repositories to be added to a GitHub Actions runner group via the API by a user without access to those repositories. This results in the repository names being shown in the UI. To exploit this, an attacker needs access to the GHES instance, permissions to modify GitHub Actions runner groups, and must successfully guess the obfuscated ID of private repositories.
Recommendations
For GitHub Enterprise Server versions 3.3 through 3.3.16, update to version 3.3.17.
For GitHub Enterprise Server versions 3.4 through 3.4.11, update to version 3.4.12.
For GitHub Enterprise Server versions 3.5 through 3.5.8, update to version 3.5.9.
For GitHub Enterprise Server versions 3.6 through 3.6.4, update to version 3.6.5.
As a temporary workaround, consider restricting access to the GitHub Actions runner group API until a patch is applied.
Correção
Exposure of Resource to Wrong Sphere
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Github Enterprise Server