Loading HuntDB...

GHSA-w49g-9f3f-c384

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, and labels of any issue inside a public repository. This was only exploitable inside a public repository. This vulnerability affected GitHub Enterprise Server versions before 3.14 and was fixed in versions 3.13.3, 3.12.8, and 3.11.14. Versions 3.10 of GitHub Enterprise Server are not affected. This vulnerability was reported via the GitHub Bug Bounty program.

Related CVEs

Key Information

GHSA ID
GHSA-w49g-9f3f-c384
Published
August 20, 2024 9:30 PM
Last Modified
September 27, 2024 6:32 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 16, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.