漏洞标题
GitHub 企业服务器中的路径遍历导致远程代码执行
漏洞描述信息
GitHub Enterprise Server中的路径遍历导致远程代码执行
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
Path traversal in GitHub Enterprise Server leading to remote code execution
漏洞描述信息
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to versions 3.8 and was fixed in versions 3.7.7, 3.6.10, 3.5.14, and 3.4.17. This vulnerability was reported via the GitHub Bug Bounty program.
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
漏洞类别
对路径名的限制不恰当(路径遍历)
漏洞标题
GitHub Enterprise Server 路径遍历漏洞
漏洞描述信息
GitHub Enterprise Server是美国GitHub开源的一个应用软件。提供一个将自己的GitHub实例设置为虚拟设备,从而提供可扩展,易于管理的平台。 GitHub Enterprise Server 3.8之前版本存在安全漏洞,该漏洞源于在存在路径遍历漏洞。
CVSS信息
N/A
漏洞类别
路径遍历