Back

MEDIUM

Incomplete cache verification issue in GitHub Enterprise Server leading to exposure of private repo files

Published Nov 1, 2022

Description

An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to access private repository files through a public repository. To exploit this, an actor would need to already be authorized on the GitHub Enterprise Server instance, be able to create a public repository, and have a site administrator visit a specially crafted URL. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.6 and was fixed in versions 3.2.20, 3.3.15, 3.4.10, 3.5.7, 3.6.3. This vulnerability was reported via the GitHub Bug Bounty program.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_P
Published Nov 1, 2022
Updated May 6, 2025
Reserved Jan 19, 2022

CISA Vulnrichment

Updated May 6, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_P
Published Nov 1, 2022
Updated May 6, 2025

GitHub

No data