Horizon Alert
Summary of the vulnerability and why it matters
A security vulnerability in GitHub Enterprise Server's notebook viewer could allow an attacker to execute code on the server. This is achieved by exploiting a flaw that enables the redirection of requests to internal services, with timing information then used to extract secrets that facilitate code execution.
- A server flaw enables secret extraction and code execution.
- This impacts how we secure development platforms.
- Confirm if our GitHub Enterprise Server is affected.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by sending a specially crafted URL to the notebook viewer, which processes user-supplied links. Although the viewer checks the URL's scheme and host, it overlooks the port number. This allows an attacker to redirect requests to internal services running on the same appliance. While direct response bodies aren't returned, the timing of responses can reveal sensitive instance secrets, enabling an attacker to gain remote code execution.
- Requires network access to the instance.
- Triggered by viewing a crafted notebook.
- Can lead to sensitive data exposure and RCE.
Live Threat
Current exploitation, exposure, and threat context
The notebook viewer in GitHub Enterprise Server could allow an attacker to extract instance secrets by timing server responses. These secrets, when combined with network access to the instance, could enable remote code execution on the appliance. This risk is supported when network access to the instance is available and private mode is disabled or when an authenticated user is present if private mode is enabled.
- Instance secrets and administrative control.
- Timing responses to infer secrets.
- Remote code execution on the appliance.
Operational Fix
Recommended remediation, mitigation, and detection steps
GitHub Enterprise Server administrators and the platform team are likely responsible for managing this vulnerability. The first practical step is to inventory all GitHub Enterprise Server instances, confirm their network exposure and business criticality, and identify the accountable owner for each instance before planning remediation.
- Platform and administrators own the issue.
- Verify instance reachability and criticality first.
- Plan remediation based on identified risk.