CVE-2024-5795

HIGH

GitHub Enterprise Server < 3.14 - Denial of Service via Large Payload to Git Server

Title source: llm
STIX 2.1

Description

A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause unbounded resource exhaustion by sending a large payload to the Git server. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in version 3.13.1, 3.12.6, 3.11.12, 3.10.14, and 3.9.17. This vulnerability was reported via the GitHub Bug Bounty program.

Scores

CVSS v3 7.7
EPSS 0.0056
EPSS Percentile 42.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (2)
github/enterprise_server 3.13.0
github/enterprise_server 3.9.0 - 3.9.17
Published Jul 16, 2024
Tracked Since Feb 18, 2026