HomeGithubCVE-2024-10824

CVE-2024-10824

MEDIUM
6.0CVSS
Published: 2024-11-07
Updated: 2025-08-27
AI Analysis

Description

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauthorized internal users to access sensitive secret scanning alert data intended only for business owners. This issue could be exploited only by organization members with a personal access token (PAT) and required that secret scanning be enabled on user-owned repositories. This vulnerability affected GitHub Enterprise Server versions after 3.13.0 but prior to 3.14.0 and was fixed in version 3.13.2.

CVSS Metrics

Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:M/U:Amber
Attack Vector
network
Complexity
low
Privileges
low
User Action
none
Confidentiality
undefined
Integrity
undefined
Availability
undefined
Weaknesses
CWE-862

Metadata

Primary Vendor
GITHUB
Published
11/7/2024
Last Modified
8/27/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

github : enterprise_server

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2024-10824 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com