404-html
, would display the error page and not the user's profile.GitHub Enterprise Server 2.14 will be deprecated as of July 12, 2019 That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, upgrade to the newest version of GitHub Enterprise Server as soon as possible.
Thanks!
The GitHub Team
A CRITICAL vulnerability was identified that allows an attacker to authorize an OAuth application on the account of a targeted user without the approval of the targeted user. This would allow an attacker to execute actions on behalf of the targeted user via the authorized OAuth application. The attacker would need to be able to create an OAuth application on the affected GitHub Enterprise Server instance to perform this attack. Additionally, to execute the attack, the targeted user would need to visit an attacker controlled website.
The affected supported versions are:
We strongly recommend upgrading your GitHub Enterprise Server appliance to the latest patch release in your series, GitHub Enterprise Server 2.14.24, 2.15.17, 2.16.12, 2.17.3, or greater immediately. If you have any questions, please contact GitHub support at https://enterprise.github.com/support.
This vulnerability was reported through the GitHub Security Bug Bounty program.
Thanks!
The GitHub Team
Thanks!
The GitHub Team
Thanks!
The GitHub Team
Thanks!
The GitHub Team
Thanks!
The GitHub Team
Thanks!
The GitHub Team
ghe-repl-promote
will now prompt for confirmation. To promote a replica without confirmation, use the -y
flag: ghe-repl-promote -y
.Thanks!
The GitHub Team
Thanks!
The GitHub Team
A CRITICAL issue was identified in Rails that allows an attacker to send a specially crafted request that could allow arbitrary files to be read and the file content to be disclosed.
The affected supported versions are:
All older, no longer supported versions are also affected.
We strongly urge upgrading your GitHub Enterprise Server appliance to the latest patch release in your series, GitHub Enterprise Server 2.13.22, 2.14.16, 2.15.9, 2.16.4, or greater immediately. If you have any questions, please contact GitHub support at https://enterprise.github.com/support.
Thanks!
The GitHub Team
Thanks!
The GitHub Team
babeld.log
, gitauth.log
, production.log
, resqued.log
and unicorn.log
log files were truncated when forwarded to a central log server.Thanks!
The GitHub Team
Thanks!
The GitHub Team
ghe-migrator
we not automatically re-indexed so weren't returned in the search results until manually re-indexed.ghe-migrator
that contains references to another pull request the user does not have access to.Thanks!
The GitHub Team
404 Not Found
errors were shown in the browser console for some script requests when using the code editor.ghe-migrator
failed when the creator of a card on the board no longer exists on the source instance.ghe-migrator
could lead to an incorrect mapping between links to pull requests and the correct pull requests.ghe-migrator
would fail with a 500 Internal Server Error.Thanks!
The GitHub Team
/var/log/error
was not automatically rotated with logrotate and could sometimes use too much disk space.POST /repos/:owner/:repo/pulls
REST API endpoint could return a 502 Bad Gateway response due to using suboptimal query indexes.ghe-migrator
fails when the creator of a card on the board no longer exists on the source instance.Thanks!
The GitHub Team
__init__
, was removed in code blocks in MediaWiki-formatted pages.manifest.json
file instead of being redirected to the correct location in the user interface.ghe-migrator
fails when the creator of a card on the board no longer exists on the source instance. (updated 2018-11-21)/etc/resolvconf/resolv.conf.d/head
(updated 2018-12-19)Thanks!
The GitHub Team
grep: /etc/github/repl-state: No such file or directory
.ghe-migrator
fails when the creator of the protected branch no longer exists on the source instance.ghe-migrator
fails when the creator of a card on the board no longer exists on the source instance. (updated 2018-11-21)/etc/resolvconf/resolv.conf.d/head
(updated 2018-12-19)Thanks!
The GitHub Team
git
package has been updated to detect malicious Git submodules that could be used to exploit CVE-2018-17456.ghe-config-apply
contained innocuous and misleading error messages about WARNING: Setting ES auto_expand_replicas failed
.500 Internal Sever Error
.osqueryi
utility has been added to the GitHub Enterprise environment.ghe-migrator
fails when the creator of the protected branch no longer exists on the source instance. (updated 2018-10-31)ghe-migrator
fails when the creator of a card on the board no longer exists on the source instance. (updated 2018-11-21)/etc/resolvconf/resolv.conf.d/head
(updated 2018-12-19)Thanks!
The GitHub Team
jekyll-remote-theme
gem of GitHub Pages could allow users to display the content of local files.ghe-repl-setup
allowed re-adding the same node as a replica.gzip
encoding.Connection timed out
if the hookshot service was unable to run migrations due to a firewall update that ran out of order.ghe-repl-status
./etc/hosts
.plain
authentication method.ghe-config-check
would hang if run without any arguments.hookshot
logs weren't purged properly in Elasticsearch and could consume large amounts of disk space.ghe-migrator
could fail to complete trying to add the same label to an issue.500 Internal Server Error
if a reviewer is no longer a member of the GitHub Enterprise environment.ghe-restore
.ghe-migrator
fails when the creator of the protected branch no longer exists on the source instance. (updated 2018-10-31)ghe-migrator
fails when the creator of a card on the board no longer exists on the source instance. (updated 2018-11-21)/etc/resolvconf/resolv.conf.d/head
(updated 2018-12-19)Thanks!
The GitHub Team
window.opener
when linking from GitHub Enterprise hosted Markdown content.ghe-repl-status
will set its exit code to 0
even when replication issues are present./etc/resolve.conf
was not respected when performing lookups.GitHub Enterprise 2.11 will be deprecated as of September 13, 2018. That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, upgrade to the newest version of GitHub Enterprise as soon as possible.
ghe-migrator
fails when the creator of the protected branch no longer exists on the source instance. (updated 2018-10-31)ghe-migrator
fails when the creator of a card on the board no longer exists on the source instance. (updated 2018-11-21)/etc/resolvconf/resolv.conf.d/head
(updated 2018-12-19)Thanks!
The GitHub Team
A CRITICAL issue was identified that allows an attacker with repository write access to create Pages sites that can display the content of system files. This could used to further escalate the vulnerability to execute arbitrary commands on the GitHub Enterprise appliance.
The affected supported versions are:
GitHub Enterprise 2.11 is not vulnerable.
We strongly recommend upgrading your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.12.18, 2.13.10, 2.14.4, or greater.
window.opener
when linking from GitHub Enterprise hosted Markdown content.ghe-snmpv3-remove-user
did not remove all account data, preventing administrators from updating the password for the SNMPv3 user.ghe-set-password
command could result in unexpected shell behavior.GitHub Enterprise 2.11 will be deprecated as of September 13, 2018. That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, upgrade to the newest version of GitHub Enterprise as soon as possible.
ghe-migrator
fails when the creator of the protected branch no longer exists on the source instance. (updated 2018-10-31)ghe-migrator
fails when the creator of a card on the board no longer exists on the source instance. (updated 2018-11-21)Thanks!
The GitHub Team
A CRITICAL issue was identified that allows an attacker with repository admin or owner privileges to execute arbitrary commands on the appliance.
The affected supported versions are:
GitHub Enterprise 2.14.3, 2.13.9, and 2.12.17 were not patched properly and are still vulnerable to the file path traversal vulnerability. GitHub Enterprise 2.14.4, 2.13.10, and 2.12.18 will ship next week to address this vulnerability. As a manual workaround, you can disable Pages on the GitHub Enterprise environment. (updated 2018-08-23)
A CRITICAL issue was identified that allows an attacker with repository write access to create Pages sites that can display the content of system files. This could used to further escalate the vulnerability to execute arbitrary commands on the GitHub Enterprise appliance.
The affected supported versions are:
GitHub Enterprise 2.11 is not vulnerable.
We strongly recommend upgrading your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.12.17, 2.13.9 or 2.14.3.
Due to a change in the implementation on GitHub Enterprise 2.12 and later, it is not possible to apply the same fix to GitHub Enterprise 2.11 for the remote code execution vulnerability. We strongly recommend upgrading GitHub Enterprise 2.11 to 2.12 or newer.
ghe-repl-status
, used to query the status of a high availability status, failed with a parse error: Invalid numeric literal at line 1, column 3
error.500 Internal Server Error
.waagent
and walinuxagent
.ghe-org-admin-promote
command-line utility would fail when attempting to promote a user without two-factor-authentication enabled as an admin of an org where two-factor authentication is required.GitHub Enterprise 2.11 will be deprecated as of September 13, 2018. That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, upgrade to the newest version of GitHub Enterprise as soon as possible.
ghe-migrator
fails when the creator of the protected branch no longer exists on the source instance. (updated 2018-10-31)ghe-migrator
fails when the creator of a card on the board no longer exists on the source instance. (updated 2018-11-21)Thanks!
The GitHub Team
ghe-support-upload
or ghe-cluster-support-upload
with sudo
would set restrictive permissions on a temporary directory preventing subsequent execution of these commands by the admin user.406 Not Acceptable
.500 Internal Server Error
.connect
timeout has been increased to allow up to four retries during a cluster restore.ghe-migrator
fails when the creator of the protected branch no longer exists on the source instance. (updated 2018-10-31)ghe-migrator
fails when the creator of a card on the board no longer exists on the source instance. (updated 2018-11-21)Thanks!
The GitHub Team
ghe-repl-status
reported a harmless error, parse error: Invalid numeric literal at line 1, column 3
.Starting with GitHub Enterprise 2.17.0, support for GitHub Services will be deprecated and administrators will not be able to install or configure new GitHub Services. Existing GitHub Services from a previous version of GitHub Enterprise will continue to function but GitHub Enterprise will not be providing any security or bug fixes to the GitHub Services functionality. At this time, there will be no changes to the existing functionality, but a warning banner will be displayed with the deprecation announcement blog post. Administrators can see which repositories are using GitHub Services with ghe-legacy-github-services-report
.
ghe-migrator
fails when the creator of the protected branch no longer exists on the source instance. (updated 2018-10-31)ghe-migrator
fails when the creator of a card on the board no longer exists on the source instance. (updated 2018-11-21)Thanks!
The GitHub Team
Host
header when requesting a Pages site would return a 404 error.0
./stafftools/users/ldap
had layout and accessibility issues./var/log/github/audit.log
has been updated to output audit events only when there has been a change.babeld.log
has been updated to include the X-Forwarded-For
and ts
(timestamp) metadata.GitHub Enterprise 2.14 requires at least GitHub Enterprise Backup Utilities 2.14.0 for Backups and Disaster Recovery.
Starting with GitHub Enterprise 2.17.0, support for GitHub Services will be deprecated and administrators will not be able to install or configure new GitHub Services. Existing GitHub Services from a previous version of GitHub Enterprise will continue to function but GitHub Enterprise will not be providing any security or bug fixes to the GitHub Services functionality. At this time, there will be no changes to the existing functionality, but a warning banner will be displayed with the deprecation announcement blog post. Administrators can see which repositories are using GitHub Services with ghe-legacy-github-services-report
. (updated 2017-07-24)
Support for Internet Explorer 11 will be deprecated on September 13, 2018.
ghe-repl-status
could report a harmless error, parse error: Invalid numeric literal at line 1, column 3
. (updated 2018-07-17)ghe-migrator
fails when the creator of the protected branch no longer exists on the source instance. (updated 2018-10-31)ghe-migrator
fails when the creator of a card on the board no longer exists on the source instance. (updated 2018-11-21)Thanks!
The GitHub Team