Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-46646


Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get a check run" API endpoint. This vulnerability did not allow unauthorized access to any repository content besides the name. This vulnerability affected GitHub Enterprise Server version 3.7.0 and above and was fixed in version 3.17.19, 3.8.12, 3.9.7 3.10.4, and 3.11.0.


Published

2023-12-21T21:15:08.620

Last Modified

2024-12-16T19:07:42.750

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-639
  • Type: Primary
    CWE-639

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application github enterprise_server < 3.7.19 Yes
Application github enterprise_server < 3.8.12 Yes
Application github enterprise_server < 3.9.7 Yes
Application github enterprise_server < 3.10.4 Yes

References