{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-10-02T09:52:06.478","vulnerabilities":[{"cve":{"id":"CVE-2024-1084","sourceIdentifier":"product-cna@github.com","published":"2024-02-13T19:15:09.053","lastModified":"2026-06-17T07:03:24.587","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site Scripting in the tag name pattern field in the tag protections UI in GitHub Enterprise Server allows a malicious website that requires user interaction and social engineering to make changes to a user account via CSP bypass with created CSRF tokens. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12  and was fixed in all versions of 3.11.5, 3.10.7, 3.9.10, and 3.8.15. This vulnerability was reported via the GitHub Bug Bounty program.\n\n"},{"lang":"es","value":"Cross-Site Scripting en el campo de patrón de nombre de etiqueta en la interfaz de usuario de protección de etiquetas en GitHub Enterprise Server permiten que un sitio web malicioso que requiere interacción del usuario e ingeniería social realice cambios en una cuenta de usuario a través de la omisión de CSP con tokens CSRF creados. Esta vulnerabilidad afectó a todas las versiones de GitHub Enterprise Server anteriores a la 3.12 y se solucionó en todas las versiones 3.11.5, 3.10.7, 3.9.10 y 3.8.15. Esta vulnerabilidad se informó a través del programa GitHub Bug Bounty."}],"affected":[{"source":"product-cna@github.com","affectedData":[{"vendor":"GitHub","product":"Enterprise Server","defaultStatus":"affected","versions":[{"version":"3.8","lessThanOrEqual":"3.8.14","versionType":"semver","status":"affected","changes":[{"at":"3.8.15","status":"unaffected"}]},{"version":"3.9","lessThanOrEqual":"3.9.9","versionType":"semver","status":"affected","changes":[{"at":"3.9.10","status":"unaffected"}]},{"version":"3.10","lessThanOrEqual":"3.10.6","versionType":"semver","status":"affected","changes":[{"at":"3.10.7","status":"unaffected"}]},{"version":"3.11","lessThanOrEqual":"3.11.4","versionType":"semver","status":"affected","changes":[{"at":"3.11.5","status":"unaffected"}]},{"version":"3.12","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"product-cna@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.3,"impactScore":3.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-02-15T20:50:39.100882Z","id":"CVE-2024-1084","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"product-cna@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*","versionEndExcluding":"3.8.15","matchCriteriaId":"DC6BA1DD-5194-4738-B23D-07FCEAFFB3DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9.0","versionEndExcluding":"3.9.10","matchCriteriaId":"8C3BDFFD-8A83-4D52-8A6E-B87B8070A046"},{"vulnerable":true,"criteria":"cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10.0","versionEndExcluding":"3.10.7","matchCriteriaId":"EB406BB2-7ABF-4A44-830F-7012CDB3D81D"},{"vulnerable":true,"criteria":"cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*","versionStartIncluding":"3.11.0","versionEndExcluding":"3.11.5","matchCriteriaId":"0529566C-AC2F-4385-93D7-578230AC453E"}]}]}],"references":[{"url":"https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.7","source":"product-cna@github.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.5","source":"product-cna@github.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://docs.github.com/en/enterprise-server@3.8/admin/release-notes#3.8.15","source":"product-cna@github.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.10","source":"product-cna@github.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.7","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.5","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://docs.github.com/en/enterprise-server@3.8/admin/release-notes#3.8.15","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.10","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}}]}