PT-2025-17245 · Github · Github Enterprise Server

CVE-2025-3246

·

Publicado

2025-04-17

·

Atualizado

2025-10-01

CVSS v4.0

8.6

Alta

VetorAV:N/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions GitHub Enterprise Server version 3.16.1
Description An improper neutralization of input issue was identified in GitHub Enterprise Server, allowing cross-site scripting in GitHub Markdown that used $$..$$ math blocks. Exploitation required access to the target GitHub Enterprise Server instance and privileged user interaction with the malicious elements.
Recommendations For version 3.16.1, update to version 3.16.2 to resolve the issue. As a temporary workaround, consider restricting the use of $$..$$ math blocks in GitHub Markdown until the update is applied.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-05159
CVE-2025-3246

Produtos afetados

Github Enterprise Server