CVE-2024-5815
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
16/07/2024
Last modified:
17/09/2024
Description
A Cross-Site Request Forgery vulnerability in GitHub Enterprise Server allowed write operations on a victim-owned repository by exploiting incorrect request types. A mitigating factor is that the attacker would have to be a trusted GitHub Enterprise Server user, and the victim would have to visit a tag in the attacker&#39;s fork of their own repository. vulnerability affected all versions of GitHub Enterprise Server prior 3.14 and was fixed in version 3.13.1, 3.12.6, 3.11.12, 3.10.14, and 3.9.17.<br />
<br />
<br />
This vulnerability was reported via the GitHub Bug Bounty program.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* | 3.9.0 (including) | 3.9.17 (excluding) |
| cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* | 3.10.0 (including) | 3.10.14 (excluding) |
| cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* | 3.11.0 (including) | 3.11.12 (excluding) |
| cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* | 3.12.0 (including) | 3.12.6 (excluding) |
| cpe:2.3:a:github:enterprise_server:3.13.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.9.17
- https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.10.14
- https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.11.12
- https://docs.github.com/en/enterprise-server@3.13/admin/release-notes#3.12.6
- https://docs.github.com/en/enterprise-server@3.13/admin/release-notes#3.13.1



