CVE-2024-10001
A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious code into the query selector via the identity property in the message handling function. This enabled the exfiltration of sensitive data by manipulating the DOM, including authentication tokens. To execute the attack, the victim must be logged into GitHub and interact with the attacker controlled malicious webpage containing the hidden iframe.
Leer descripción completaMostrar menos
This vulnerability occurs due to an improper sequence of validation, where the origin check occurs after accepting the user-controlled identity property. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.11.16, 3.12.10, 3.13.5, 3.14.2, and 3.15.0. This vulnerability was reported via the GitHub Bug Bounty program.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 7.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.39%
- Percentil entre todas las CVEs puntuadas: 30
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1203Exploitation for Client Executionexecution90 % - Impacto principal
T1059Command and Scripting Interpreterexecution85 % - Impacto secundario
T1005Data from Local Systemcollection88 % - Impacto secundario
T1552.007Container APIcredential access92 %
XSS con inyección de código mediante iframe malicioso que requiere interacción del usuario (UI:P). Exfiltración de tokens de autenticación y datos sensibles del DOM.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-94
Referencias
- https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.17
- https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.11
- https://docs.github.com/en/enterprise-server@3.13/admin/release-notes#3.13.6
- https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.3
- https://docs.github.com/en/enterprise-server@3.15/admin/release-notes#3.15.0
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-10001",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-10001",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-02-12T16:49:39.191533Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.2,
"exploitabilityScore": 2.8
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "product-cna@github.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 7.1,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "PASSIVE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "product-cna@github.com",
"affectedData": [
{
"vendor": "GitHub",
"product": "Enterprise Server",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "3.11.17",
"status": "unaffected"
}
],
"version": "3.11.0",
"versionType": "semver",
"lessThanOrEqual": "3.11.16"
},
{
"status": "affected",
"changes": [
{
"at": "3.12.11",
"status": "unaffected"
}
],
"version": "3.12.0",
"versionType": "semver",
"lessThanOrEqual": "3.12.10"
},
{
"status": "affected",
"changes": [
{
"at": "3.13.6",
"status": "unaffected"
}
],
"version": "3.13.0",
"versionType": "semver",
"lessThanOrEqual": "3.13.5"
},
{
"status": "affected",
"changes": [
{
"at": "3.14.3",
"status": "unaffected"
}
],
"version": "3.14.0",
"versionType": "semver",
"lessThanOrEqual": "3.14.2"
},
{
"status": "affected",
"changes": [
{
"at": "3.15.1",
"status": "unaffected"
}
],
"version": "3.15.0",
"versionType": "semver",
"lessThanOrEqual": "3.15.1"
}
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-01-29T19:15:18.360",
"references": [
{
"url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.17",
"tags": [
"Release Notes"
],
"source": "product-cna@github.com"
},
{
"url": "https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.11",
"tags": [
"Release Notes"
],
"source": "product-cna@github.com"
},
{
"url": "https://docs.github.com/en/enterprise-server@3.13/admin/release-notes#3.13.6",
"tags": [
"Release Notes"
],
"source": "product-cna@github.com"
},
{
"url": "https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.3",
"tags": [
"Release Notes"
],
"source": "product-cna@github.com"
},
{
"url": "https://docs.github.com/en/enterprise-server@3.15/admin/release-notes#3.15.0",
"tags": [
"Release Notes"
],
"source": "product-cna@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "product-cna@github.com",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious code into the query selector via the identity property in the message handling function. This enabled the exfiltration of sensitive data by manipulating the DOM, including authentication tokens. To execute the attack, the victim must be logged into GitHub and interact with the attacker controlled malicious webpage containing the hidden iframe. This vulnerability occurs due to an improper sequence of validation, where the origin check occurs after accepting the user-controlled identity property. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.11.16, 3.12.10, 3.13.5, 3.14.2, and 3.15.0. This vulnerability was reported via the GitHub Bug Bounty program."
},
{
"lang": "es",
"value": "Se identificó una vulnerabilidad de inyección de código en GitHub Enterprise Server que permitía a los atacantes inyectar código malicioso en el selector de consultas a través de la propiedad de identidad en la función de gestión de mensajes. Esto permitió la exfiltración de datos confidenciales mediante la manipulación de los tokens de autenticación DOM, incluida. Para ejecutar el ataque, la víctima debe iniciar sesión en GitHub e interactuar con la página web maliciosa controlada por el atacante que contiene el iframe oculto. Esta vulnerabilidad se produce debido a una secuencia incorrecta de validación, donde la verificación de origen se produce después de aceptar la propiedad de identidad controlada por el usuario. Esta vulnerabilidad afectó a todas las versiones de GitHub Enterprise Server anteriores a 3.11.16, 3.12.10, 3.13.5, 3.14.2 y 3.15.0. Esta vulnerabilidad se informó a través del programa GitHub Bug Bounty."
}
],
"lastModified": "2026-06-17T06:54:44.387",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB550802-6704-4D1B-9E98-75DFE784BF7A",
"versionEndExcluding": "3.11.6"
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F70645DE-4DC2-40CB-B425-4E002B302FDB",
"versionEndExcluding": "3.12.10",
"versionStartIncluding": "3.12.0"
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B08CBD2C-6DA7-4C0F-9812-42933F51C003",
"versionEndExcluding": "3.13.5",
"versionStartIncluding": "3.13.0"
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "59E74193-93FE-45FE-8C74-34EC30EEB03C",
"versionEndExcluding": "3.14.2",
"versionStartIncluding": "3.14.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "product-cna@github.com"
}