CVE-2020-10516
Summary
| CVE | CVE-2020-10516 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-03 14:15:00 UTC |
| Updated | 2020-06-05 14:38:00 UTC |
| Description | An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissions and gain access to unauthorized repositories within an organization. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.21 and was fixed in 2.20.9, 2.19.15, and 2.18.20. This vulnerability was reported via the GitHub Bug Bounty program. |
Risk And Classification
Problem Types: CWE-552
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitHub Enterprise - The best way to build and ship software | MISC | enterprise.github.com | Release Notes, Third Party Advisory |
| GitHub Enterprise - The best way to build and ship software | MISC | enterprise.github.com | Release Notes, Third Party Advisory |
| GitHub Enterprise - The best way to build and ship software | MISC | enterprise.github.com | Release Notes, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Vaibhav Singh
There are currently no legacy QID mappings associated with this CVE.