A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise have access to in the Security Overview in GitHub Advanced Security. The Security Overview was required to be filtered only using the `archived:` filter and all other access controls were functioning normally. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.17 and was fixed in versions 3.13.14, 3.14.11, 3.15.6, and 3.16.2.
Metrics
Affected Vendors & Products
References
History
Fri, 18 Apr 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 17 Apr 2025 23:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise have access to in the Security Overview in GitHub Advanced Security. The Security Overview was required to be filtered only using the `archived:` filter and all other access controls were functioning normally. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.17 and was fixed in versions 3.13.14, 3.14.11, 3.15.6, and 3.16.2. | |
Title | Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized access to private repository names | |
Weaknesses | CWE-862 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_P
Published:
Updated: 2025-04-18T12:02:10.223Z
Reserved: 2025-04-02T14:11:42.860Z
Link: CVE-2025-3124

Updated: 2025-04-18T11:45:50.312Z

Status : Received
Published: 2025-04-17T23:15:41.593
Modified: 2025-04-17T23:15:41.593
Link: CVE-2025-3124

No data.