QID 379525
Date Published: 2024-03-27
QID 379525: GitHub Enterprise Server Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-2748)
GitHub provides hosting for software development version control using Git.
CVE-2024-2748: A Cross Site Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker to execute unauthorized actions on behalf of an unsuspecting user.
Affected Versions:
GitHub Enterprise Server version 3.12.0
QID Detection Logic:
It checks for vulnerable versions of the GitHub Enterprise Server.
Successful exploitation of this vulnerability may allow an attacker to execute unauthorized actions on behalf of an unsuspecting user.
Solution
Please refer to GitHub advisory release-notes#3.12.1
Vendor References
- release-notes#3.12.1 -
docs.github.com/en/[email protected]/admin/release-notes#3.12.1
CVEs related to QID 379525
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Enterprise Server 3.12.1 |
|