CVE Published: 16/07/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: GitHub_P |
Vendor: GitHub |
Product: GitHub Enterprise Server Status : PUBLISHED
CVE-2024-5566 Description
An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes defined on the related Personal Access Token. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in version 3.13.1, 3.12.6, 3.11.12, 3.10.14, and 3.9.17.
Metrics
CVSS Version: 3.1 |
Base Score: 5.8 MEDIUM Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
l➤ Exploitability Metrics: Attack Vector (AV)* NETWORK Attack Complexity (AC)* HIGH Privileges Required (PR)* HIGH User Interaction (UI)* NONE Scope (S)* CHANGED