CVE-2024-5566: Improper Privilege Management allows for access to unauthorized repository content during migration
An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes defined on the related Personal Access Token. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in version 3.13.1, 3.12.6, 3.11.12, 3.10.14, and 3.9.17.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitHub Enterprise Serverto a version that resolves this vulnerability.Fixed in 3.13.1 - Upgrade
Upgrade
GitHub Enterprise Serverto a version that resolves this vulnerability.Fixed in 3.12.6 - Upgrade
Upgrade
GitHub Enterprise Serverto a version that resolves this vulnerability.Fixed in 3.11.12 - Upgrade
Upgrade
GitHub Enterprise Serverto a version that resolves this vulnerability.Fixed in 3.10.14 - Upgrade
Upgrade
GitHub Enterprise Serverto a version that resolves this vulnerability.Fixed in 3.9.17
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5566?
The severity of CVE-2024-5566 is considered moderate due to the improper privilege management issue affecting repository migration.
How do I fix CVE-2024-5566?
To fix CVE-2024-5566, upgrade to GitHub Enterprise Server version 3.14 or later.
Which versions of GitHub Enterprise Server are affected by CVE-2024-5566?
CVE-2024-5566 affects all versions of GitHub Enterprise Server prior to 3.14.
What type of vulnerability is CVE-2024-5566?
CVE-2024-5566 is an improper privilege management vulnerability.
What impact does CVE-2024-5566 have on users?
CVE-2024-5566 allows users to migrate private repositories without the appropriate scopes on their Personal Access Tokens.