Impact
A missing authorization flaw in GitHub Enterprise Server allows an authenticated user with write permissions on any repository to read sensitive metadata from private repositories they normally cannot access. The attacker can retrieve private owners, repository names, branch names, commit SHAs, commit messages, and the actor who performed the push, leading to a confidentiality breach of internal project information. This issue is rooted in an unchecked delegated bypass endpoint that resolves rule suites using attacker-supplied identifiers.
Affected Systems
GitHub Enterprise Server installations running any version prior to 3.22 are vulnerable. The vulnerability is fixed in releases 3.17.18, 3.18.12, 3.19.9, 3.20.5, and 3.21.3, so any deployment using earlier or unpatched minor versions must be updated.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation under normal conditions. Although the flaw requires an authenticated user with write access, the attacker can enumerate sequential rule‑suite identifiers to target multiple private repositories. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment