MEDIUM
An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags
Published Sep 23, 2024
6.2
MEDIUMCVSS 4.0
EPSS 0.45%
Description
An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.
Affected products
-
- Version 3.10.0StatusaffectedConstraints<=3.10.16
- Version 3.11.0StatusaffectedConstraints<=3.11.14
- Version 3.12.0StatusaffectedConstraints<=3.12.8
- Version 3.13.0StatusaffectedConstraints<=3.13.3
- Version 3.14StatusaffectedConstraints<=3.14.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| GitHub | GitHub Enterprise Server | affected |
|
OR
- ≥ 3.10.0 · < 3.10.17
- ≥ 3.11.0 · < 3.11.15
- ≥ 3.12.0 · < 3.12.9
- ≥ 3.13.0 · < 3.13.4
- 3.14.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.17 Release Notes
- https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.15 Release Notes
- https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.9 Release Notes
- https://docs.github.com/en/enterprise-server@3.13/admin/release-notes#3.13.4 Release Notes
- https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.1 Release Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49052 Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_P
Published Sep 23, 2024
Updated Sep 23, 2024
Reserved Aug 28, 2024
Link CVE-2024-8263
CISA Vulnrichment
Updated Sep 23, 2024
ENISA EUVD
EUVD-2024-49052 Assigner GitHub_P
Published Sep 23, 2024
Updated Sep 23, 2024
Exploited since n/a
Link EUVD-2024-49052