QID 379178
Date Published: 2024-01-24
QID 379178: GitHub Enterprise Server Multiple Security Vulnerabilites (release-notes#3.7.19)
GitHub provides hosting for software development version control using Git.
CVE-2023-46645: A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when building a GitHub Pages site.
CVE-2023-6746: An insertion of sensitive information into log file vulnerability was identified in the log files for a GitHub Enterprise Server backend service that could permit an adversary in the middle attack when combined with other phishing techniques.
CVE-2023-46646: Due to an improper access control, an attacker could view private repository names by enumerating check run IDs with the Get a check run API endpoint.
CVE-2023-51379: An incorrect authorization vulnerability was identified that allowed issue comments to be updated with an improperly scoped token.
CVE-2023-51380: An incorrect authorization vulnerability was identified that allowed issue comments to be read with an improperly scoped token.
Affected Versions:
GitHub Enterprise Server versions Prior to 3.7.19
QID Detection Logic:
It checks for vulnerable version of GitHub Enterprise Server using ghe-version command(Linux).
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed sensitive information disclosure.
- release-notes#3.7.19 -
docs.github.com/en/[email protected]/admin/release-notes#3.7.19
CVEs related to QID 379178
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| release-notes#3.7.19 |
|