An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.
History

Mon, 30 Sep 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Github
Github enterprise Server
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
cpe:2.3:a:github:enterprise_server:3.14.0:*:*:*:*:*:*:*
Vendors & Products Github
Github enterprise Server
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Mon, 23 Sep 2024 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
Description An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 6.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:L/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_P

Published: 2024-09-23T20:12:51.005Z

Updated: 2024-09-23T20:36:38.566Z

Reserved: 2024-08-28T13:59:08.440Z

Link: CVE-2024-8263

cve-icon Vulnrichment

Updated: 2024-09-23T20:36:31.949Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-23T21:15:12.957

Modified: 2024-09-30T15:57:26.213

Link: CVE-2024-8263

cve-icon Redhat

No data.