漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configuration
Vulnerability Description
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply nested YAML. When release notes were generated, the configuration file was parsed without a nesting depth limit, causing excessive resource consumption that could render the instance unresponsive. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.18, 3.18.12, 3.19.9, 3.20.5, and 3.21.3. This vulnerability was reported via the GitHub Bug Bounty program.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
GitHub Enterprise Server 资源管理错误漏洞
Vulnerability Description
GitHub enterprise server是美国GitHub公司的一款一座企业级代码托管服务器。 GitHub Enterprise Server 3.22之前版本存在资源管理错误漏洞,该漏洞源于解析发布说明配置文件时未限制嵌套深度,可能导致资源过度消耗,使实例无响应。以下版本受到影响:3.17.0版本至3.17.17版本、3.18.0版本至3.18.11版本、3.19.0版本至3.19.8版本、3.20.0版本至3.20.4版本和3.21.0版本至3.21.2版本。
CVSS Information
N/A
Vulnerability Type
N/A