Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get a check run" API endpoint. This vulnerability did not allow unauthorized access to any repository content besides the name. This vulnerability affected GitHub Enterprise Server version 3.7.0 and above and was fixed in version 3.17.19, 3.8.12, 3.9.7 3.10.4, and 3.11.0.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_P

Published: 2023-12-21T20:45:15.264Z

Updated: 2023-12-21T20:45:15.264Z

Reserved: 2023-10-24T13:41:13.389Z


Link: CVE-2023-46646

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-12-21T21:15:08.620

Modified: 2023-12-29T15:52:25.340


Link: CVE-2023-46646

JSON object: View

cve-icon Redhat Information

No data.

CWE