PT-2026-97052 · Github · Github Enterprise Server
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GitHub Enterprise Server versions 3.17 through 3.22
Description
A server-side request forgery (SSRF) issue exists in the notebook viewer. While the system validates the scheme and host of a user-supplied URL, it fails to validate the port. This allows requests to be directed to internal services listening on different ports of the same appliance. Although response bodies are not returned, response timing serves as an oracle, enabling the character-by-character extraction of instance secrets. These secrets can subsequently be used in interactions with internal services to achieve remote code execution (RCE) on the appliance. Exploitation requires network access and is unauthenticated if private mode is disabled, or requires any authenticated user if private mode is enabled.
Recommendations
Update version 3.17 to 3.17.21
Update version 3.18 to 3.18.15
Update version 3.19 to 3.19.12
Update version 3.20 to 3.20.8
Update version 3.21 to 3.21.6
Update version 3.22 to 3.22.1
Fix
RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Github Enterprise Server