A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise have access to in the Security Overview in GitHub Advanced Security. The Security Overview was required to be filtered only using the `archived:` filter and all other access controls were functioning normally. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.17 and was fixed in versions 3.13.14, 3.14.11, 3.15.6, and 3.16.2.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 05 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* | |
| Metrics | cvssV3_1 
 | 
Fri, 18 Apr 2025 12:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 17 Apr 2025 23:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise have access to in the Security Overview in GitHub Advanced Security. The Security Overview was required to be filtered only using the `archived:` filter and all other access controls were functioning normally. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.17 and was fixed in versions 3.13.14, 3.14.11, 3.15.6, and 3.16.2. | |
| Title | Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized access to private repository names | |
| Weaknesses | CWE-862 | |
| References |  | 
 | 
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_P
Published: 2025-04-17T22:50:14.017Z
Updated: 2025-04-18T12:02:10.223Z
Reserved: 2025-04-02T14:11:42.860Z
Link: CVE-2025-3124
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-04-18T11:45:50.312Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-04-17T23:15:41.593
Modified: 2025-09-05T15:00:04.687
Link: CVE-2025-3124
 Redhat
                        Redhat
                    No data.