Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Djcruz93

#40664of 53,632
6.5Total CVSS
Vulnerabilities · 1
PT-2021-15238
6.5
2021-04-02
Github · Github Enterprise Server · CVE-2021-22865
**Name of the Vulnerable Software and Affected Versions** GitHub Enterprise Server versions prior to 3.0.4 GitHub Enterprise Server versions prior to 2.22.10 GitHub Enterprise Server versions prior to 2.21.18 **Description** An improper access control issue was identified that allowed access tokens generated from a GitHub App's web authentication flow to read private repository metadata via the REST API without having been granted the appropriate permissions. To exploit this, an attacker would need to create a GitHub App and have a user authorize it, with the private repository metadata returned being limited to repositories owned by the user the token identifies. **Recommendations** For versions prior to 3.0.4, update to version 3.0.4 or later. For versions prior to 2.22.10, update to version 2.22.10 or later. For versions prior to 2.21.18, update to version 2.21.18 or later.