漏洞标题
GitHub Pages中的不安全配置选项可能导致GitHub Enterprise Server上的远程代码执行
漏洞描述信息
GitHub Pages中的不安全配置选项可能导致GitHub Enterprise Server上的远程代码执行
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Server
漏洞描述信息
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration of the underlying parsers used by GitHub Pages were not sufficiently restricted and made it possible to execute commands on the GitHub Enterprise Server instance. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.22.7 and was fixed in 2.22.7, 2.21.15, and 2.20.24. The underlying issues contributing to this vulnerability were identified through the GitHub Security Bug Bounty program.
CVSS信息
N/A
漏洞类别
在命令中使用的特殊元素转义处理不恰当(命令注入)
漏洞标题
GitHub 命令注入漏洞
漏洞描述信息
GitHub是一套面向开源及私有软件项目的托管平台。 GitHub Enterprise Server prior to 2.22.7 存在安全漏洞,攻击者可利用该漏洞远程代码执行。
CVSS信息
N/A
漏洞类别
命令注入