GitHub Enterprise Server Sensitive Information Disclosure Vulnerability

Vulnerability

A vulnerability allowing the exposure of sensitive information has been identified in GitHub Enterprise Server versions 3.17 prior to 3.17.2. This vulnerability could enable an attacker to disclose the names of private repositories within an organization. Exploitation requires an organization administrator to install a malicious GitHub App in the organization's repositories. The vulnerability can be exploited using a user-to-server token with no scopes via the Search API endpoint.

Impact

Successful exploitation allows the disclosure of private repository names within an organization.

Remediation

Users can upgrade to GitHub Enterprise Server version 3.17.2, which addresses this vulnerability.

Added: Jul 1, 2025, 7:56 PM
Updated: Jul 1, 2025, 7:56 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
2.5
exploitability
5.0
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.