CVE Vulnerabilities

CVE-2012-2055

Improper Control of Dynamically-Managed Code Resources

Published: Apr 05, 2012 | Modified: Jan 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

GitHub Enterprise before 20120304 does not properly restrict the use of a hash to provide values for a models attributes, which allows remote attackers to set the public_key[user_id] value via a modified URL for the public-key update form, related to a mass assignment vulnerability.

Weakness

The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.

Affected Software

Name Vendor Start Version End Version
Github Github * 20120304 (excluding)

Potential Mitigations

References