Threats Tagged 'ghsa-843p-hf47-6r9f'
View all threats tagged with 'ghsa-843p-hf47-6r9f'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-843p-hf47-6r9f'
Click on any threat for detailed analysis and mitigation recommendations
An authorization bypass vulnerability in GitHub Enterprise Server allowed any authenticated user to read raw diffs or patches of pull requests in private repositories without proper authorization. The issue stemmed from access tokens being scoped to repository name and pull request number rather than a globally unique repository identifier. This enabled an attacker who created a repository and pull request with matching names and numbers to access private pull request contents. The vulnerability affected all versions prior to 3.22 and was fixed in versions 3.17.21, 3.18.15, 3.19.12, 3.20.8, and 3.21.6. Exploitation required knowledge of the target repository name and a valid pull request number. The CVSS score is 6.5 (medium severity). Join the discussion | GCVE Database | 09/22/2026, 21:31:30 UTC Added: 10/03/2026, 17:22:11 UTC |
Showing 1 to 1 of 1 result