CVE-2024-8263
CVE-2024-8263
An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:L/SI:H/SA:N
Productos afectados
GitHub · GitHub Enterprise Server¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.17https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.15https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.9https://docs.github.com/en/enterprise-server@3.13/admin/release-notes#3.13.4https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.1