An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, and labels of any issue inside a public repository. This was only exploitable inside a public repository. This vulnerability affected GitHub Enterprise Server versions before 3.14 and was fixed in versions 3.13.3, 3.12.8, and 3.11.14. Versions 3.10 of GitHub Enterprise Server are not affected. This vulnerability was reported via the GitHub Bug Bounty program.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 27 Sep 2024 18:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Github Github enterprise Server | |
| CPEs | cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* | |
| Vendors & Products | Github Github enterprise Server | |
| Metrics | cvssV3_1 
 | 
Tue, 20 Aug 2024 20:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Tue, 20 Aug 2024 19:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, and labels of any issue inside a public repository. This was only exploitable inside a public repository. This vulnerability affected GitHub Enterprise Server versions before 3.14 and was fixed in versions 3.13.3, 3.12.8, and 3.11.14. Versions 3.10 of GitHub Enterprise Server are not affected. This vulnerability was reported via the GitHub Bug Bounty program. | |
| Weaknesses | CWE-863 | |
| References |  | |
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_P
Published: 2024-08-20T19:17:37.776Z
Updated: 2024-08-20T19:46:55.283Z
Reserved: 2024-08-12T18:11:15.883Z
Link: CVE-2024-7711
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-20T19:46:52.845Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-08-20T20:15:10.173
Modified: 2024-09-27T18:17:05.577
Link: CVE-2024-7711
 Redhat
                        Redhat
                    No data.