CVE-2025-6981
15.07.2025, 21:15
An incorrect authorization vulnerability allowed unauthorized read access to the contents of internal repositories for contractor accounts when the Contractors API feature was enabled. The Contractors API is a rarely-enabled feature in private preview. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.18 and was fixed in versions 3.14.15,3.15.10,3.16.6 and3.17.3Enginsight
Vendor | Product | Version |
---|---|---|
github | enterprise_server | 𝑥 < 3.14.5 |
github | enterprise_server | 3.15.0 ≤ 𝑥 < 3.15.10 |
github | enterprise_server | 3.16.0 ≤ 𝑥 < 3.16.6 |
github | enterprise_server | 3.17.0 ≤ 𝑥 < 3.17.3 |
𝑥
= Vulnerable software versions
References