An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes defined on the related Personal Access Token. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in version 3.13.1, 3.12.6, 3.11.12, 3.10.14, and 3.9.17.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Enterprise_server | Github | 3.9.0 (including) | 3.9.17 (excluding) |
Enterprise_server | Github | 3.10.0 (including) | 3.10.14 (excluding) |
Enterprise_server | Github | 3.11.0 (including) | 3.11.12 (excluding) |
Enterprise_server | Github | 3.12.0 (including) | 3.12.6 (excluding) |
Enterprise_server | Github | 3.13.0 (including) | 3.13.0 (including) |