PT-2024-6118 · Github · Github Enterprise Server
Ahacker1
·
Published
2024-08-20
·
Updated
2024-09-27
·
CVE-2024-7711
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
GitHub Enterprise Server versions prior to 3.14
GitHub Enterprise Server versions 3.13.3, 3.12.8, and 3.11.14 are not vulnerable, but versions before these are affected.
Description
An Incorrect Authorization issue was identified, allowing an attacker to update the title, assignees, and labels of any issue inside a public repository. This issue was only exploitable inside a public repository and was reported via the GitHub Bug Bounty program.
Recommendations
For GitHub Enterprise Server versions prior to 3.14, update to version 3.13.3, 3.12.8, or 3.11.14 to resolve the issue.
As a temporary workaround, consider restricting access to public repositories until a patch is applied.
Avoid using the issue update functionality in public repositories until the issue is resolved.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Github Enterprise Server