- Description
- An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting in GitHub Markdown that used `$$..$$` math blocks. Exploitation required access to the target GitHub Enterprise Server instance and privileged user interaction with the malicious elements. This vulnerability affected version 3.16.1 of GitHub Enterprise Server and was fixed in version 3.16.2. This vulnerability was reported via the GitHub Bug Bounty program.
- Source
- product-cna@github.com
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 8.6
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
- product-cna@github.com
- CWE-79
- Hype score
- Not currently trending
GitHub Enterprise の脆弱性 CVE-2025-3509 などが FIX:コード実行や認証バイパスなどの可能性 https://t.co/sAZgbzsP7Z GitHub Enterprise の3件の脆弱性が FIX しました。なかでも、XSS の脆弱性 CVE-2025-3246 は、CVSS 値が 8.6
@iototsecnews
5 May 2025
98 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Threat Alert: GitHub Enterprise Server Vulnerabilities Expose Risk of Code Execution and Data CVE-2025-3509 CVE-2025-3124 CVE-2025-3246 Severity: 🔴 High Maturity: 💢 Emerging Learn more: https://t.co/Qf1erF9WDW #CyberSecurity #ThreatIntel #InfoSec
@fletch_ai
22 Apr 2025
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2025-3246 🔴 HIGH (8.6) 🏢 GitHub - GitHub Enterprise Server 🏗️ 3.16 🔗 https://t.co/N3VPHglP3H #CyberCron #VulnAlert #InfoSec https://t.co/z9s7bd61De
@cybercronai
18 Apr 2025
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes