A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause unbounded resource exhaustion by sending a large payload to the Git server. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in version 3.13.1, 3.12.6, 3.11.12, 3.10.14, and 3.9.17. This vulnerability was reported via the GitHub Bug Bounty program.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 09:48
Type | Values Removed | Values Added |
---|---|---|
References | () https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.14 - Release Notes | |
References | () https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.12 - Release Notes | |
References | () https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.6 - Release Notes | |
References | () https://docs.github.com/en/enterprise-server@3.13/admin/release-notes#3.13.1 - Release Notes | |
References | () https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.17 - Release Notes | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.7 |
17 Sep 2024, 16:24
Type | Values Removed | Values Added |
---|---|---|
First Time |
Github
Github enterprise Server |
|
CPE | cpe:2.3:a:github:enterprise_server:3.13.0:*:*:*:*:*:*:* cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* |
|
References | () https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.14 - Release Notes | |
References | () https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.12 - Release Notes | |
References | () https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.6 - Release Notes | |
References | () https://docs.github.com/en/enterprise-server@3.13/admin/release-notes#3.13.1 - Release Notes | |
References | () https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.17 - Release Notes | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
Summary |
|
16 Jul 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-16 22:15
Updated : 2024-11-21 09:48
NVD link : CVE-2024-5795
Mitre link : CVE-2024-5795
CVE.ORG link : CVE-2024-5795
JSON object : View
Products Affected
github
- enterprise_server
CWE
CWE-400
Uncontrolled Resource Consumption