A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via social engineering. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Sep 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Github
Github enterprise Server |
|
CPEs | cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* cpe:2.3:a:github:enterprise_server:3.14.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Github
Github enterprise Server |
|
Metrics |
cvssV3_1
|
Mon, 23 Sep 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 23 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via social engineering. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program. | |
Weaknesses | CWE-79 | |
References |
|
|
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: GitHub_P
Published: 2024-09-23T20:09:01.746Z
Updated: 2024-09-23T20:37:07.272Z
Reserved: 2024-09-12T22:04:09.227Z
Link: CVE-2024-8770
Vulnrichment
Updated: 2024-09-23T20:37:01.371Z
NVD
Status : Analyzed
Published: 2024-09-23T21:15:13.123
Modified: 2024-09-27T13:49:29.690
Link: CVE-2024-8770
Redhat
No data.