Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized read-only access
Vulnerability Description
An incorrect authorization vulnerability allowed unauthorized read access to the contents of internal repositories for contractor accounts when the Contractors API feature was enabled. The Contractors API is a rarely-enabled feature in private preview. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.18 and was fixed in versions 3.14.15, 3.15.10, 3.16.6 and 3.17.3
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-6981
Credits & Attribution
No credits recorded in the NVD database.
References
- https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.15
- https://docs.github.com/en/enterprise-server@3.15/admin/release-notes#3.15.10
- https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.6
- https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.3
More from GitHub
View All →Affected Vendor
GitHub
View all reports →