CVE-2024-1482
Github
CVE-2024-1482 is a security vulnerability in GitHub Enterprise Server related to incorrect authorization. This flaw allows an attacker with access to the Enterprise Server to create new branches in public repositories and execute arbitrary GitHub Actions workflows using the GITHUB_TOKEN permissions. Despite a moderate CVSS score of 6.5, the SOCRadar Vulnerability Risk Score (SVRS) is 30, indicating a relatively low immediate threat, but continuous monitoring is still needed. The vulnerability affected GitHub Enterprise Server versions after 3.8 and before 3.12, now patched in versions 3.9.10, 3.10.7, and 3.11.5. Successful exploitation could lead to unauthorized code execution and potential data compromise, highlighting the importance of applying the security patches. It is important for security teams to assess their exposure and update their GitHub Enterprise Server instances promptly. The vulnerability was reported through the GitHub Bug Bounty program showing the importance of responsible disclosure programs.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.