在 GitHub Enterprise Server 中发现了一个缺失的身份验证漏洞,该漏洞允许具有写入权限的仓库协作者通过 GraphQL API 删除当前的默认分支,从而导致攻击者控制的分支成为新的默认分支。在要求拉取请求(PR)审查但未限制分支删除的仓库中,此漏洞绕过了审查要求,使得新生成的克隆仓库以及默认分支的 API 请求使用攻击者控制的代码内容。此漏洞影响了支持的 GitHub Enterprise Server 3.18、3.19、3.20、3.21 和 3.22 系列版本,并在版本 3.18.16、
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GitHub | Enterprise Server | 3.18.0 ~ 3.18.* | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet