GitHub Enterprise Server Path Traversal Vulnerability
CVE-2024-1082

6.3MEDIUM

Key Information:

Vendor

Github

Vendor
CVE Published:
13 February 2024

What is CVE-2024-1082?

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker to gain unauthorized read permission to files by deploying arbitrary symbolic links to a GitHub Pages site with a specially crafted artifact tarball. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.8.15, 3.9.10, 3.10.7, 3.11.5. This vulnerability was reported via the GitHub Bug Bounty program.

Affected Version(s)

Enterprise Server 3.8.0

Enterprise Server 3.8.0 < 3.8.15

Enterprise Server 3.9.0 < 3.9.10

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

yvvdwf
.