GitHub App installed in organizations could upgrade some permissions from read to write access without approval from an organization administrator. An attacker would require an account with administrator access to install a malicious GitHub App. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versions 3.14.1, 3.13.4, 3.12.9, 3.11.15, and 3.10.17. This vulnerability was reported via the GitHub Bug Bounty program.
Configuration 1 (hide)
|
27 Aug 2025, 16:33
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Github
Github enterprise Server |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| CPE | cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* cpe:2.3:a:github:enterprise_server:3.14.0:*:*:*:*:*:*:* |
|
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.10.17 - Release Notes | |
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.11.15 - Release Notes | |
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.12.9 - Release Notes | |
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.13.4 - Release Notes | |
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.14.1 - Release Notes |
08 Nov 2024, 19:01
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
07 Nov 2024, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2024-11-07 22:15
Updated : 2025-08-27 16:33
NVD link : CVE-2024-8810
Mitre link : CVE-2024-8810
CVE.ORG link : CVE-2024-8810
JSON object : View
Improper Privilege Management