An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissions and gain access to unauthorized repositories within an organization. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.21 and was fixed in 2.20.9, 2.19.15, and 2.18.20. This vulnerability was reported via the GitHub Bug Bounty program.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_P

Published: 2020-06-03T13:31:24

Updated: 2024-08-04T11:06:09.534Z

Reserved: 2020-03-12T00:00:00

Link: CVE-2020-10516

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-06-03T14:15:12.377

Modified: 2020-06-05T14:38:02.673

Link: CVE-2020-10516

cve-icon Redhat

No data.