QID 379447
Date Published: 2024-03-18
QID 379447: GitHub Enterprise Server Privilege Escalation Vulnerability (CVE-2024-1908)
GitHub provides hosting for software development version control using Git.
CVE-2024-1908: An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use the Enterprise Actions GitHub Connect download token to fetch private repository data. An attacker would require an account on the server instance with non-default settings for GitHub Connect.
Affected Versions:
GitHub Enterprise Server version 3.8.0 to 3.8.15.
GitHub Enterprise Server version 3.9.0 to 3.9.10.
GitHub Enterprise Server version 3.10.0 to 3.10.7.
GitHub Enterprise Server version 3.11.0 to 3.11.5.
QID Detection Logic:
It checks for vulnerable versions of the GitHub Enterprise Server.
Successful exploitation of this vulnerability may allow an attacker to use the Enterprise Actions GitHub Connect download token to fetch private repository data.
- release-notes#3.10.8 -
docs.github.com/en/[email protected]/admin/release-notes#3.10.8 - release-notes#3.11.6 -
docs.github.com/en/[email protected]/admin/release-notes#3.11.6 - release-notes#3.8.16 -
docs.github.com/en/[email protected]/admin/release-notes#3.8.16 - release-notes#3.9.11 -
docs.github.com/en/[email protected]/admin/release-notes#3.9.11
CVEs related to QID 379447
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Enterprise Server 3.10.8 |
|
||
| Enterprise Server 3.11.6 |
|
||
| Enterprise Server 3.8.16 |
|
||
| Enterprise Server 3.9.11 |
|