CVE-2024-8770
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via social engineering. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.
A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via social engineering. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-09-12 CVE Reserved
- 2024-09-23 CVE Published
- 2024-09-23 CVE Updated
- 2025-04-01 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
- CAPEC-63: Cross-Site Scripting (XSS)
References (5)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
GitHub Search vendor "GitHub" | GitHub Enterprise Server Search vendor "GitHub" for product "GitHub Enterprise Server" | 3.14.0 Search vendor "GitHub" for product "GitHub Enterprise Server" and version "3.14.0" | en |
Affected
| ||||||
GitHub Search vendor "GitHub" | GitHub Enterprise Server Search vendor "GitHub" for product "GitHub Enterprise Server" | >= 3.13.0 <= 3.13.3 Search vendor "GitHub" for product "GitHub Enterprise Server" and version " >= 3.13.0 <= 3.13.3" | en |
Affected
| ||||||
GitHub Search vendor "GitHub" | GitHub Enterprise Server Search vendor "GitHub" for product "GitHub Enterprise Server" | >= 3.12.0 <= 3.12.8 Search vendor "GitHub" for product "GitHub Enterprise Server" and version " >= 3.12.0 <= 3.12.8" | en |
Affected
| ||||||
GitHub Search vendor "GitHub" | GitHub Enterprise Server Search vendor "GitHub" for product "GitHub Enterprise Server" | >= 3.11.0 <= 3.11.14 Search vendor "GitHub" for product "GitHub Enterprise Server" and version " >= 3.11.0 <= 3.11.14" | en |
Affected
| ||||||
GitHub Search vendor "GitHub" | GitHub Enterprise Server Search vendor "GitHub" for product "GitHub Enterprise Server" | >= 3.10.0 <= 3.10.16 Search vendor "GitHub" for product "GitHub Enterprise Server" and version " >= 3.10.0 <= 3.10.16" | en |
Affected
|