GitHub Enterprise before 20120304 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the public_key[user_id] value via a modified URL for the public-key update form, related to a "mass assignment" vulnerability.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NGitHub
APPGithub< 20120304
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References
Related vulnerabilities
CVE-2020-10516CRITICAL9.8PL ✓same product
Eskalacja uprawnień w GitHub Enterprise Server API
CVE-2017-18365CRITICAL9.8PL ✓same product
RCE poprzez deserializację w GitHub Enterprise Management Console
CVE-2021-22863HIGH8.1same product
An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allow...
CVE-2020-10519HIGH8.8same product
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when ...
CVE-2020-10518HIGH8.8same product
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when ...