[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2024-2440Date: (C)2024-04-22   (M)2024-04-23


A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on a detached repository by making a GraphQL mutation to alter repository permissions while the repository is detached.��This vulnerability affected all versions of GitHub Enterprise Server prior to 3.13 and was fixed in versions 3.9.13, 3.10.10, 3.11.8 and 3.12.1.��This vulnerability was reported via the GitHub Bug Bounty program.

Reference:
https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.10
https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.8
https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.2
https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.13

© SecPod Technologies