CVE-2020-10517
Improper access control in GitHub Enterprise Server leading to the enumeration of private repository names
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to determine the names of unauthorized private repositories given their numerical IDs. This vulnerability did not allow unauthorized access to any repository content besides the name. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.22 and was fixed in versions 2.21.6, 2.20.15, and 2.19.21. This vulnerability was reported via the GitHub Bug Bounty program.
Se identificó una vulnerabilidad de control de acceso inapropiado en GitHub Enterprise Server que permitió a usuarios autenticados de la instancia determinar los nombres de los repositorios privados no autorizados dados sus ID numéricos. Esta vulnerabilidad no permitía el acceso no autorizado a ningún contenido del repositorio además del nombre. Esta vulnerabilidad afectó a todas las versiones de GitHub Enterprise Server anteriores a la 2.22 y se corrigió en las versiones 2.21.6, 2.20.15 y 2.19.21. Esta vulnerabilidad se reportó por medio del programa GitHub Bug Bounty
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-03-12 CVE Reserved
- 2020-08-27 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-285: Improper Authorization
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://enterprise.github.com/releases/2.19.21/notes | 2021-10-07 | |
https://enterprise.github.com/releases/2.20.15/notes | 2021-10-07 | |
https://enterprise.github.com/releases/2.21.6/notes | 2021-10-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Github Search vendor "Github" | Github Search vendor "Github" for product "Github" | < 2.19.21 Search vendor "Github" for product "Github" and version " < 2.19.21" | enterprise |
Affected
| ||||||
Github Search vendor "Github" | Github Search vendor "Github" for product "Github" | >= 2.20.0 < 2.20.15 Search vendor "Github" for product "Github" and version " >= 2.20.0 < 2.20.15" | enterprise |
Affected
| ||||||
Github Search vendor "Github" | Github Search vendor "Github" for product "Github" | >= 2.21.0 < 2.21.6 Search vendor "Github" for product "Github" and version " >= 2.21.0 < 2.21.6" | enterprise |
Affected
|