PT-2024-21917 · Github · Github Enterprise Server
Adrianoapj
·
Published
2024-03-20
·
Updated
2024-03-26
·
CVE-2024-2748
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GitHub Enterprise Server version 3.12.0
Description
A Cross Site Request Forgery issue was identified that allowed an attacker to execute unauthorized actions on behalf of an unsuspecting user, with the mitigating factor that user interaction is required. This issue was reported via the GitHub Bug Bounty program.
Recommendations
For GitHub Enterprise Server version 3.12.0, update to version 3.12.1 to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the server to minimize the risk of exploitation.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Github Enterprise Server