CVE-2020-10516
Improper access control in GitHub Enterprise Server leading to privilege escalation of organization member
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissions and gain access to unauthorized repositories within an organization. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.21 and was fixed in 2.20.9, 2.19.15, and 2.18.20. This vulnerability was reported via the GitHub Bug Bounty program.
Se identificó una vulnerabilidad de control de acceso inapropiado en la API de GitHub Enterprise Server, que permitió a un miembro de la organización escalar permisos y conseguir acceso a repositorios no autorizados dentro de una organización. Esta vulnerabilidad afectó a todas las versiones de GitHub Enterprise Server anteriores a 2.21 y fue corregida en las versiones 2.20.9, 2.19.15 y 2.18.20. Esta vulnerabilidad fue reportada por medio del programa GitHub Bug Bounty.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-03-12 CVE Reserved
- 2020-06-03 CVE Published
- 2024-04-07 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-285: Improper Authorization
- CWE-552: Files or Directories Accessible to External Parties
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://enterprise.github.com/releases/2.18.20/notes | Release Notes | |
https://enterprise.github.com/releases/2.19.15/notes | Release Notes | |
https://enterprise.github.com/releases/2.20.9/notes | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Github Search vendor "Github" | Github Search vendor "Github" for product "Github" | >= 2.18.0 < 2.18.20 Search vendor "Github" for product "Github" and version " >= 2.18.0 < 2.18.20" | enterprise |
Affected
| ||||||
Github Search vendor "Github" | Github Search vendor "Github" for product "Github" | >= 2.19.0 < 2.19.15 Search vendor "Github" for product "Github" and version " >= 2.19.0 < 2.19.15" | enterprise |
Affected
| ||||||
Github Search vendor "Github" | Github Search vendor "Github" for product "Github" | >= 2.20.0 < 2.20.9 Search vendor "Github" for product "Github" and version " >= 2.20.0 < 2.20.9" | enterprise |
Affected
|