CVE-2024-8770 MEDIUM

CVE-2024-8770

Vendor Github
Product GitHub Enterprise Server
Weakness CWE-79 · XSS
Published September 23, 2024
Last update September 23, 2024

CVSS base score

5.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:L/SI:N/SA:N

What the vulnerability does

01Description

A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via social engineering. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.

Key dates

02Disclosure timeline

September 23, 2024 CVE published
September 23, 2024 Record updated

Related vulnerabilities

04Related CVE