Description

Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents

Description source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListBefore 1.27.0affected
GitHub AdvisoryBefore 1.27.0 · Fixed in 1.27.0affected

References

4