CVE-2012-2055: High severity github enterprise vulnerability
GitHub Enterprise before 20120304 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the publickey[userid] value via a modified URL for the public-key update form, related to a "mass assignment" vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2055?
CVE-2012-2055 is considered to be of medium severity due to its potential for unauthorized access to user attributes.
How do I fix CVE-2012-2055?
To fix CVE-2012-2055, you should upgrade GitHub Enterprise to version 20120304 or later.
What type of vulnerability is CVE-2012-2055?
CVE-2012-2055 is classified as a mass assignment vulnerability that affects the way user attributes can be set.
Who is affected by CVE-2012-2055?
Users of GitHub Enterprise versions prior to 20120304 are affected by CVE-2012-2055.
What can attackers do exploiting CVE-2012-2055?
Attackers exploiting CVE-2012-2055 can manipulate a URL to set unauthorized values for a user's public key.