CVE 5.3 MEDIUM

Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized read-only access_CVE-2025-6981

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N

Description

An incorrect authorization vulnerability allowed unauthorized read access to the contents of internal repositories for contractor accounts when the Contractors API feature was enabled. The Contractors API is a rarely-enabled feature in private preview. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.18 and was fixed in versions 3.14.15,Β 3.15.10,Β 3.16.6 andΒ 3.17.3

Basic Information

ID CVE-2025-6981
Source GitHub_P
Published Jul 15, 2025 at 20:44
Modified Jul 16, 2025 at 19:04

Affected Product

Vendor GitHub
Product Enterprise Server
Version 3.14.0
Affected Versions GitHub Enterprise Server 3.14.0
GitHub Enterprise Server 3.15.0
GitHub Enterprise Server 3.16.0
GitHub Enterprise Server 3.17.0

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.