HIGH🇵🇱 Wersja polska

CVE-2020-10518

CVSS 8.8v3.1pub. 2020-08-27upd. 2024-11-21

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration of the underlying parsers used by GitHub Pages were not sufficiently restricted and made it possible to execute commands on the GitHub Enterprise Server instance. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.22 and was fixed in 2.21.6, 2.20.15, and 2.19.21. The underlying issues contributing to this vulnerability were identified both internally and through the GitHub Security Bug Bounty program.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • GitHub

    APP
    Github
    < 2.19.212.20.0 – 2.20.15 (excl.)2.21.0 – 2.21.6 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2020-10516CRITICAL9.8PL ✓same product

Eskalacja uprawnień w GitHub Enterprise Server API

CVE-2017-18365CRITICAL9.8PL ✓same product

RCE poprzez deserializację w GitHub Enterprise Management Console

CVE-2021-22863HIGH8.1same product

An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allow...

CVE-2020-10519HIGH8.8same product

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when ...

CVE-2012-2055HIGH7.5same product

GitHub Enterprise before 20120304 does not properly restrict the use of a hash to provide values for a model's...