PT-2026-97047 · Github · Github Enterprise Server
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GitHub Enterprise Server versions prior to 3.22
Description
An authorization bypass allows authenticated users to read the raw diff or patch of pull requests in private repositories. This occurs because access tokens for these resources are scoped to the repository name and pull request number instead of a globally unique repository identifier. An attacker knowing a target repository name and a valid pull request number can create a matching repository and pull request to use their own token to retrieve the private contents.
Recommendations
Update to version 3.17.21
Update to version 3.18.15
Update to version 3.19.12
Update to version 3.20.8
Update to version 3.21.6
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Github Enterprise Server