GitHub enterprise server是美国GitHub公司的一款一座企业级代码托管服务器。 GitHub Enterprise Server 3.22之前版本存在授权问题漏洞,该漏洞源于授权检查不正确,只验证目标仓库的读取权限而未验证令牌安装是否显式拥有该仓库访问权限,攻击者获取受害者的用户到服务器令牌后可在任何公共仓库上创建问题、评论等写操作。以下版本受到影响:3.16.0版本至3.16.19版本、3.17.0版本至3.17.16版本、3.18.0版本至3.18.10版本、3.19.0版本至
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GitHub | Enterprise Server | 3.16.0≤ 3.16.19 |
affected |
3.17.0≤ 3.17.16 |
affected | ||
3.18.0≤ 3.18.10 |
affected | ||
3.19.0≤ 3.19.7 |
affected | ||
3.20.0≤ 3.20.3 |
affected | ||
3.21.0≤ 3.21.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GitHub | Enterprise Server | 3.16.0 ~ 3.16.19 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet