PT-2025-27576 · Github · Github Enterprise Server
Ammar Bandukwala
+1
·
Published
2025-07-01
·
Updated
2025-09-05
·
CVE-2025-6600
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
GitHub Enterprise Server version 3.17
Description:
An exposure of sensitive information issue was identified that could allow an attacker to disclose the names of private repositories within an organization. This issue could be exploited by leveraging a user-to-server token with no scopes via the "Search API" endpoint. Successful exploitation required an organization administrator to install a malicious GitHub App in the organization’s repositories.
Recommendations:
For GitHub Enterprise Server version 3.17, update to version 3.17.2 to resolve the issue. As a temporary workaround, consider restricting the installation of GitHub Apps to trusted sources until the update is applied. Restrict access to the Search API endpoint to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Github Enterprise Server