An incorrect authorization vulnerability allowed unauthorized read access to the contents of internal repositories for contractor accounts when the Contractors API feature was enabled. The Contractors API is a rarely-enabled feature in private preview. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.18 and was fixed in versions 3.14.15, 3.15.10, 3.16.6 and 3.17.3
References
Configurations
Configuration 1 (hide)
|
History
27 Aug 2025, 14:41
Type | Values Removed | Values Added |
---|---|---|
References | () https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.15 - Release Notes | |
References | () https://docs.github.com/en/enterprise-server@3.15/admin/release-notes#3.15.10 - Release Notes | |
References | () https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.6 - Release Notes | |
References | () https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.3 - Release Notes | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
CPE | cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* | |
First Time |
Github
Github enterprise Server |
16 Jul 2025, 14:58
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
15 Jul 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-15 21:15
Updated : 2025-08-27 14:41
NVD link : CVE-2025-6981
Mitre link : CVE-2025-6981
CVE.ORG link : CVE-2025-6981
JSON object : View
Products Affected
github
- enterprise_server
CWE
CWE-863
Incorrect Authorization