- Description
- A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute arbitrary code by exploiting the pre-receive hook functionality, potentially leading to privilege escalation and system compromise. The vulnerability involves using dynamically allocated ports that become temporarily available, such as during a hot patch upgrade. This means the vulnerability is only exploitable during specific operational conditions, which limits the attack window. Exploitation required either site administrator permissions to enable and configure pre-receive hooks or a user with permissions to modify repositories containing pre-receive hooks where this functionality was already enabled. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.18 and was fixed in versions 3.17.1, 3.16.4, 3.15.8, 3.14.13, 3.13.16. This vulnerability was reported via the GitHub Bug Bounty program.
- Source
- product-cna@github.com
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 7.1
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber
- Severity
- HIGH
- product-cna@github.com
- CWE-94
- Hype score
- Not currently trending
GitHub Enterprise の脆弱性 CVE-2025-3509 などが FIX:コード実行や認証バイパスなどの可能性 https://t.co/sAZgbzsP7Z GitHub Enterprise の3件の脆弱性が FIX しました。なかでも、XSS の脆弱性 CVE-2025-3246 は、CVSS 値が 8.6
@iototsecnews
5 May 2025
98 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Threat Alert: GitHub Enterprise Server Vulnerabilities Expose Risk of Code Execution and Data CVE-2025-3509 CVE-2025-3124 CVE-2025-3246 Severity: 🔴 High Maturity: 💢 Emerging Learn more: https://t.co/Qf1erF9WDW #CyberSecurity #ThreatIntel #InfoSec
@fletch_ai
22 Apr 2025
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2025-3509 🔴 HIGH (7.1) 🏢 GitHub - Enterprise Server 🏗️ 3.13.0 🔗 https://t.co/i7JFchQSzD 🔗 https://t.co/pLem9uszZZ 🔗 https://t.co/oGYJBkdj8t 🔗 https://t.co/N3VPHglP3H #CyberCron #VulnAlert #InfoSec https://t.co/1WvT8tM2cv
@cybercronai
18 Apr 2025
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes