An incorrect authorization vulnerability allowed unauthorized read access to the contents of internal repositories for contractor accounts when the Contractors API feature was enabled. The Contractors API is a rarely-enabled feature in private preview. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.18 and was fixed in versions 3.14.15, 3.15.10, 3.16.6 and 3.17.3
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
Tue, 15 Jul 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An incorrect authorization vulnerability allowed unauthorized read access to the contents of internal repositories for contractor accounts when the Contractors API feature was enabled. The Contractors API is a rarely-enabled feature in private preview. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.18 and was fixed in versions 3.14.15, 3.15.10, 3.16.6 and 3.17.3 | |
Title | Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized read-only access | |
Weaknesses | CWE-863 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_P
Published: 2025-07-15T20:44:30.022Z
Updated: 2025-07-16T19:04:18.464Z
Reserved: 2025-07-01T18:28:24.614Z
Link: CVE-2025-6981

Updated: 2025-07-16T19:04:13.924Z

Status : Awaiting Analysis
Published: 2025-07-15T21:15:34.630
Modified: 2025-07-16T14:58:59.837
Link: CVE-2025-6981

No data.