Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2024-6337
GitHub Enterprise Server vulnerability analysis and mitigation

Overview

An Incorrect Authorization vulnerability (CVE-2024-6337) was identified in GitHub Enterprise Server that allowed a GitHub App with only content: read and pull_request_write: write permissions to read issue content inside a private repository. This vulnerability was discovered and reported through the GitHub Bug Bounty program, affecting all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versions 3.13.3, 3.12.8, 3.11.14, and 3.10.16. The vulnerability was only exploitable via user access token, while installation access token was not impacted (NVD).

Technical details

The vulnerability has been assigned CWE-863 (Incorrect Authorization) and received a CVSS v3.1 Base Score of 6.5 (MEDIUM) with vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N. Additionally, it received a CVSS v4.0 score of 5.9 (MEDIUM) with vector string CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/S:N (NVD).

Impact

The vulnerability allowed unauthorized access to issue content within private repositories, potentially exposing sensitive information. The impact was limited to scenarios where a GitHub App with specific limited permissions could access content beyond its intended authorization scope (NVD).

Exploitability

The vulnerability was only exploitable through user access tokens, while installation access tokens were not affected. This limitation reduced the potential attack surface, as it required specific conditions to be exploited (NVD).

Mitigation and workarounds

The vulnerability has been fixed in GitHub Enterprise Server versions 3.13.3, 3.12.8, 3.11.14, and 3.10.16. Organizations using affected versions should upgrade to the patched versions to mitigate this security risk (GitHub Release Notes).

Additional resources


SourceThis report was generated using AI

Related GitHub Enterprise Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-17556HIGH8.8
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesAug 05, 2026
CVE-2026-18730HIGH8.2
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 01, 2026
CVE-2026-76851HIGH7.7
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 01, 2026
CVE-2026-19118HIGH7.7
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 01, 2026
CVE-2026-15996MEDIUM6.6
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesAug 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management