

Cloudflare Service Abused by Indian APT ‘SloppyLemming’ in Attacks Against Pakistan – Active IOCs
September 26, 2024
Bitter APT – Active IOCs
September 26, 2024
Cloudflare Service Abused by Indian APT ‘SloppyLemming’ in Attacks Against Pakistan – Active IOCs
September 26, 2024
Bitter APT – Active IOCs
September 26, 2024Severity
Medium
Analysis Summary
CVE-2024-8770 CVSS:5.8
GitHub Enterprise Server is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed> in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVE-2024-8263 CVSS:6.2
GitHub Enterprise Server could allow a remote authenticated attacker to bypass security restrictions, caused by an improper privilege management vulnerability. By using an improperly scoped PAT through the use of nested tagsewsdwed4s, an attacker could exploit this vulnerability to cause arbitrary workflows to be committed.
Impact
- Cross-Site Scripting
- Security Bypass
Indicators of Compromise
CVE
- CVE-2024-8770
- CVE-2024-8263
Affected Vendors
Affected Products
- GitHub Enterprise Server - 3.14.0
- GitHub Enterprise Server - 3.13.3
- GitHub Enterprise Server - 3.12.8
- GitHub Enterprise Server - 3.11.14
- GitHub Enterprise Server - 3.10.16
Remediation
Upgrade to the latest version of GitHub Enterprise Server, available from the GitHub Website.