← Back

CVE-2024-7711

nvd nist
Published: Aug 20, 2024Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:L/U:Amber
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:L/U:AmberShow less
Source: CNA (Secondary)

Description

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, and labels of any issue inside a public repository. This was only exploitable inside a public repository. This vulnerability affected GitHub Enterprise Server versions before 3.14 and was fixed in versions 3.13.3, 3.12.8, and 3.11.14. Versions 3.10 of GitHub Enterprise Server are not affected. This vulnerability was reported via the GitHub Bug Bounty program.

Affected (3)

1 product
Enterprise Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Github
From 3.11.0 to 3.11.14
From 3.12.0 to 3.12.8
From 3.13.0 to 3.13.3

References (3)

Source: product-cna@github.com
Release NotesVendor Advisory
Source: product-cna@github.com
Release NotesVendor Advisory
Source: product-cna@github.com
Release NotesVendor Advisory

Timeline

No history available yet.