CRITICAL🇵🇱 Wersja polska

CVE-2020-10516

CVSS 9.8v3.1pub. 2020-06-03upd. 2024-11-21

An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissions and gain access to unauthorized repositories within an organization. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.21 and was fixed in 2.20.9, 2.19.15, and 2.18.20. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • GitHub

    APP
    Github
    2.18.0 – 2.18.20 (excl.)2.19.0 – 2.19.15 (excl.)2.20.0 – 2.20.9 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2017-18365CRITICAL9.8PL ✓same product

RCE poprzez deserializację w GitHub Enterprise Management Console

CVE-2021-22863HIGH8.1same product

An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allow...

CVE-2020-10519HIGH8.8same product

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when ...

CVE-2020-10518HIGH8.8same product

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when ...

CVE-2012-2055HIGH7.5same product

GitHub Enterprise before 20120304 does not properly restrict the use of a hash to provide values for a model's...