CVE-2024-8263: Medium severity github enterprise vulnerability
An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8263?
CVE-2024-8263 has a moderate severity level due to improper privilege management allowing arbitrary workflows to be committed.
How do I fix CVE-2024-8263?
To fix CVE-2024-8263, upgrade your GitHub Enterprise Server to version 3.10.17, 3.11.15, 3.12.9, 3.13.4, or 3.14.1.
Which versions of GitHub Enterprise Server are affected by CVE-2024-8263?
CVE-2024-8263 affects all versions of GitHub Enterprise Server prior to 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1.
What type of vulnerability is CVE-2024-8263?
CVE-2024-8263 is classified as an improper privilege management vulnerability.
Can I use nested tags with CVE-2024-8263 vulnerability?
Using nested tags in GitHub Enterprise Server may expose systems to CVE-2024-8263 if the software is not updated to the fixed versions.