CVE-2020-10517
Status: ModifiedMedium (4.3)—
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to determine the names of unauthorized private repositories given their numerical IDs. This vulnerability did not allow unauthorized access to any repository content besides the name. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.22 and was fixed in versions 2.21.6, 2.20.15, and 2.19.21. This vulnerability was reported via the GitHub Bug Bounty program.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Base score: 4.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.05%
- Percentile among all scored CVEs: 63
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-285
- NVD-CWE-noinfo
References
- https://enterprise.github.com/releases/2.19.21/notes
- https://enterprise.github.com/releases/2.20.15/notes
- https://enterprise.github.com/releases/2.21.6/notes
- https://enterprise.github.com/releases/2.19.21/notes
- https://enterprise.github.com/releases/2.20.15/notes
- https://enterprise.github.com/releases/2.21.6/notes
Raw JSON (NVD)
Show
{
"id": "CVE-2020-10517",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "product-cna@github.com",
"affectedData": [
{
"vendor": "GitHub",
"product": "GitHub Enterprise Server",
"versions": [
{
"status": "affected",
"version": "2.21",
"lessThan": "2.21.6",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.20",
"lessThan": "2.20.15",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.19",
"lessThan": "2.19.21",
"versionType": "custom"
}
]
}
]
}
],
"published": "2020-08-27T22:15:09.770",
"references": [
{
"url": "https://enterprise.github.com/releases/2.19.21/notes",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "product-cna@github.com"
},
{
"url": "https://enterprise.github.com/releases/2.20.15/notes",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "product-cna@github.com"
},
{
"url": "https://enterprise.github.com/releases/2.21.6/notes",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "product-cna@github.com"
},
{
"url": "https://enterprise.github.com/releases/2.19.21/notes",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://enterprise.github.com/releases/2.20.15/notes",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://enterprise.github.com/releases/2.21.6/notes",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "product-cna@github.com",
"description": [
{
"lang": "en",
"value": "CWE-285"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to determine the names of unauthorized private repositories given their numerical IDs. This vulnerability did not allow unauthorized access to any repository content besides the name. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.22 and was fixed in versions 2.21.6, 2.20.15, and 2.19.21. This vulnerability was reported via the GitHub Bug Bounty program."
},
{
"lang": "es",
"value": "Se identificó una vulnerabilidad de control de acceso inapropiado en GitHub Enterprise Server que permitió a usuarios autenticados de la instancia determinar los nombres de los repositorios privados no autorizados dados sus ID numéricos. Esta vulnerabilidad no permitía el acceso no autorizado a ningún contenido del repositorio además del nombre. Esta vulnerabilidad afectó a todas las versiones de GitHub Enterprise Server anteriores a la 2.22 y se corrigió en las versiones 2.21.6, 2.20.15 y 2.19.21. Esta vulnerabilidad se reportó por medio del programa GitHub Bug Bounty"
}
],
"lastModified": "2026-06-17T02:47:57.170",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:github:github:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B069227C-199F-48D2-8A3A-04FAC5BAF966",
"versionEndExcluding": "2.19.21"
},
{
"criteria": "cpe:2.3:a:github:github:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "99A2F224-E3D3-4E27-B7ED-57E544A45A8C",
"versionEndExcluding": "2.20.15",
"versionStartIncluding": "2.20.0"
},
{
"criteria": "cpe:2.3:a:github:github:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "330B13CF-E0E2-40C1-9A9F-F90A0D6E5A3C",
"versionEndExcluding": "2.21.6",
"versionStartIncluding": "2.21.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "product-cna@github.com"
}