
Cloud Vulnerability DB
A community-led vulnerabilities database
An Incorrect Authorization vulnerability (CVE-2024-6337) was identified in GitHub Enterprise Server that allowed a GitHub App with only content: read and pull_request_write: write permissions to read issue content inside a private repository. This vulnerability was discovered and reported through the GitHub Bug Bounty program, affecting all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versions 3.13.3, 3.12.8, 3.11.14, and 3.10.16. The vulnerability was only exploitable via user access token, while installation access token was not impacted (NVD).
The vulnerability has been assigned CWE-863 (Incorrect Authorization) and received a CVSS v3.1 Base Score of 6.5 (MEDIUM) with vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N. Additionally, it received a CVSS v4.0 score of 5.9 (MEDIUM) with vector string CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/S:N (NVD).
The vulnerability allowed unauthorized access to issue content within private repositories, potentially exposing sensitive information. The impact was limited to scenarios where a GitHub App with specific limited permissions could access content beyond its intended authorization scope (NVD).
The vulnerability was only exploitable through user access tokens, while installation access tokens were not affected. This limitation reduced the potential attack surface, as it required specific conditions to be exploited (NVD).
The vulnerability has been fixed in GitHub Enterprise Server versions 3.13.3, 3.12.8, 3.11.14, and 3.10.16. Organizations using affected versions should upgrade to the patched versions to mitigate this security risk (GitHub Release Notes).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."