« Volver al listado

CVE-2025-3124

Estado: AnalizadaMedia (5.3)—

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise have access to in the Security Overview in GitHub Advanced Security. The Security Overview was required to be filtered only using the `archived:` filter and all other access controls were functioning normally. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.17 and was fixed in versions 3.13.14, 3.14.11, 3.15.6, and 3.16.2.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-3124",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-3124",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-18T11:45:44.321770Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "product-cna@github.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 5.3,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "LOW",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "product-cna@github.com",
      "affectedData": [
        {
          "vendor": "GitHub",
          "product": "Enterprise Server",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "3.13.14",
                  "status": "unaffected"
                }
              ],
              "version": "3.13.0",
              "versionType": "semver",
              "lessThanOrEqual": "3.13.13"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "3.14.11",
                  "status": "unaffected"
                }
              ],
              "version": "3.14.0",
              "versionType": "semver",
              "lessThanOrEqual": "3.14.10"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "3.15.6",
                  "status": "unaffected"
                }
              ],
              "version": "3.15.0",
              "versionType": "semver",
              "lessThanOrEqual": "3.15.5"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "3.16.2",
                  "status": "unaffected"
                }
              ],
              "version": "3.16.0",
              "versionType": "semver",
              "lessThanOrEqual": "3.16.1"
            },
            {
              "status": "unaffected",
              "version": "3.17.0"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-04-17T23:15:41.593",
  "references": [
    {
      "url": "https://docs.github.com/en/enterprise-server@3.13/admin/release-notes#3.13.14",
      "tags": [
        "Release Notes"
      ],
      "source": "product-cna@github.com"
    },
    {
      "url": "https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.11",
      "tags": [
        "Release Notes"
      ],
      "source": "product-cna@github.com"
    },
    {
      "url": "https://docs.github.com/en/enterprise-server@3.15/admin/release-notes#3.15.6",
      "tags": [
        "Release Notes"
      ],
      "source": "product-cna@github.com"
    },
    {
      "url": "https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.2",
      "tags": [
        "Release Notes"
      ],
      "source": "product-cna@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "product-cna@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise have access to in the Security Overview in GitHub Advanced Security. The Security Overview was required to be filtered only using the `archived:` filter and all other access controls were functioning normally. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.17 and was fixed in versions 3.13.14, 3.14.11, 3.15.6, and 3.16.2."
    },
    {
      "lang": "es",
      "value": "Se identificó una vulnerabilidad de autorización faltante en GitHub Enterprise Server que permitía a un usuario ver los nombres de repositorios privados a los que, de otro modo, no tendría acceso en la descripción general de seguridad de GitHub Advanced Security. Esta descripción general de seguridad debía filtrarse únicamente con el filtro `archived:` y todos los demás controles de acceso funcionaban con normalidad. Esta vulnerabilidad afectó a todas las versiones de GitHub Enterprise Server anteriores a la 3.17 y se corrigió en las versiones 3.13.14, 3.14.11, 3.15.6 y 3.16.2."
    }
  ],
  "lastModified": "2026-06-17T09:19:13.863",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E45A981-5733-4DCB-B6C3-97BE212BBD06",
              "versionEndExcluding": "3.13.14"
            },
            {
              "criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C8B89DB-16A4-4DD2-9C89-62533F2F55F8",
              "versionEndExcluding": "3.14.11",
              "versionStartIncluding": "3.14.0"
            },
            {
              "criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27ECD3E6-9B4B-4E53-8CF2-FCF04FC7E0C9",
              "versionEndExcluding": "3.15.6",
              "versionStartIncluding": "3.15.0"
            },
            {
              "criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B5D5F10-62A7-4636-915F-82A5F19539E5",
              "versionEndExcluding": "3.16.2",
              "versionStartIncluding": "3.16.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "product-cna@github.com"
}