HIGH🇬🇧 English

CVE-2020-10519

CVSS 8.8v3.1pub. 2021-03-03upd. 2024-11-21

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration of the underlying parsers used by GitHub Pages were not sufficiently restricted and made it possible to execute commands on the GitHub Enterprise Server instance. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.22.7 and was fixed in 2.22.7, 2.21.15, and 2.20.24. The underlying issues contributing to this vulnerability were identified through the GitHub Security Bug Bounty program.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • GitHub

    APP
    Github
    < 2.20.242.21.0 – 2.21.15 (bez)2.22.0 – 2.22.7 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCE
CWE
Referencje

Powiązane podatności

CVE-2020-10516CRITICAL9.8PL ✓ten sam produkt

Eskalacja uprawnień w GitHub Enterprise Server API

CVE-2017-18365CRITICAL9.8PL ✓ten sam produkt

RCE poprzez deserializację w GitHub Enterprise Management Console

CVE-2021-22863HIGH8.1ten sam produkt

An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allow...

CVE-2020-10518HIGH8.8ten sam produkt

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when ...

CVE-2012-2055HIGH7.5ten sam produkt

GitHub Enterprise before 20120304 does not properly restrict the use of a hash to provide values for a model's...