QID 378566
Date Published: 2023-07-06
QID 378566: GitHub Enterprise Server Path Traversal Vulnerability
GitHub provides hosting for software development version control using Git.
An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissions and gain access to unauthorized repositories within an organization.
Affected Versions:
3.7 Prior to 3.7.6
QID Detection Logic:
It checks for vulnerable version of GitHub Enterprise Server.
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when building a GitHub Pages site.
Solution
Please refer to GitHub advisory release-notes#3.7.6
Vendor References
- release-notes#3.7.6 -
docs.github.com/en/[email protected]/admin/release-notes#3.7.6
CVEs related to QID 378566
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| release-notes#3.7.6 |
|