GitHub Enterprise Server
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*
- 3.17.0
- 3.17.1
A vulnerability allowing the exposure of sensitive information has been identified in GitHub Enterprise Server versions 3.17 prior to 3.17.2. This vulnerability could enable an attacker to disclose the names of private repositories within an organization. Exploitation requires an organization administrator to install a malicious GitHub App in the organization's repositories. The vulnerability can be exploited using a user-to-server token with no scopes via the Search API endpoint.
Successful exploitation allows the disclosure of private repository names within an organization.
Users can upgrade to GitHub Enterprise Server version 3.17.2, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.