CVE-2024-9539
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-9539 is an information disclosure vulnerability discovered in GitHub Enterprise Server. Attackers could exploit this flaw by uploading malicious SVG files and crafting a URL that, when clicked by a victim user, would reveal metadata information about the user. With this information, attackers could create convincing phishing pages to trick users into revealing sensitive data. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14, and was fixed in subsequent patches: 3.14.2, 3.13.5, 3.12.10, and 3.11.16. The vulnerability was reported through GitHub's Bug Bounty program.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.