CVE-2024-5566 MEDIUM

CVE-2024-5566: Improper Privilege Management allows for access to unauthorized repository content during migration

Vendor Github
Product GitHub Enterprise Server
Weakness CWE-269
Published July 16, 2024
Last update August 1, 2024

CVSS base score

5.8/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

What the vulnerability does

01Description

An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes defined on the related Personal Access Token. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in version 3.13.1, 3.12.6, 3.11.12, 3.10.14, and 3.9.17.

Key dates

02Disclosure timeline

July 16, 2024 CVE published
August 1, 2024 Record updated