PT-2024-21917 · Github · Github Enterprise Server

Adrianoapj

·

Published

2024-03-20

·

Updated

2024-03-26

·

CVE-2024-2748

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitHub Enterprise Server version 3.12.0
Description A Cross Site Request Forgery issue was identified that allowed an attacker to execute unauthorized actions on behalf of an unsuspecting user, with the mitigating factor that user interaction is required. This issue was reported via the GitHub Bug Bounty program.
Recommendations For GitHub Enterprise Server version 3.12.0, update to version 3.12.1 to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the server to minimize the risk of exploitation.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-2748

Affected Products

Github Enterprise Server