A
Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause unbounded resource exhaustion by sending a large payload to the Git server. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in version 3.13.1, 3.12.6, 3.11.12, 3.10.14, and 3.9.17. This vulnerability was reported via the GitHub Bug Bounty program.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 09:48
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.7 |
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.10.14 - Release Notes | |
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.11.12 - Release Notes | |
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.12.6 - Release Notes | |
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.13.1 - Release Notes | |
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.9.17 - Release Notes |
17 Sep 2024, 16:24
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:github:enterprise_server:3.13.0:*:*:*:*:*:*:* cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* |
|
| Summary |
|
|
| First Time |
Github
Github enterprise Server |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.10.14 - Release Notes | |
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.11.12 - Release Notes | |
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.12.6 - Release Notes | |
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.13.1 - Release Notes | |
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.9.17 - Release Notes |
16 Jul 2024, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-07-16 22:15
Updated : 2024-11-21 09:48
NVD link : CVE-2024-5795
Mitre link : CVE-2024-5795
CVE.ORG link : CVE-2024-5795
JSON object : View
Products Affected
CWE
CWE-400
Uncontrolled Resource Consumption