Back

MEDIUM

Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized access to private repository names

Published Apr 17, 2025

Description

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise have access to in the Security Overview in GitHub Advanced Security. The Security Overview was required to be filtered only using the `archived:` filter and all other access controls were functioning normally. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.17 and was fixed in versions 3.13.14, 3.14.11, 3.15.6, and 3.16.2.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_P
Published Apr 17, 2025
Updated Apr 18, 2025
Reserved Apr 2, 2025

CISA Vulnrichment

Updated Apr 18, 2025

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_P
Published Apr 17, 2025
Updated Apr 18, 2025

GitHub

No data