vulns.co
/
GKData.io MCP

AZAuthorization and tenant boundaries · 3 min read

GitHub comparison output lacked source-repository authorization

GitHub awarded USD 10,000 for a GHES comparison feature that exposed limited code across repository permission boundaries (vendor-report).

Read the primary source AZAuthorization and tenant boundariesReviewed 2026-10-03

Root cause

GitHub identifies improper access control in cross-repository comparison (vendor-report; vendor-release). Access to one repository did not establish permission to disclose content from another contributing repository. The vendor describes prerequisites of existing repository access and prior knowledge of private-repository references; this was not described as unrestricted anonymous browsing. The conceptual failure is authorizing a derived view without preserving every source repository’s access boundary; implementation-level check placement is not disclosed.

Demonstrated impact

The vendor confirms limited code disclosure from an otherwise unauthorized repository (vendor-report; vendor-release). The public summary does not establish complete repository extraction, write access, account takeover, or exploitation in the wild; those outcomes must not be inferred from the broader report title.

Lessons for review

  • Editorial design lesson: authorize every contributing source under the requesting actor before returning a combined or derived view.
  • Editorial review objective: ensure that permission to access one repository never substitutes for permission to read another repository’s content.
  • GitHub lists historical fixes in GHES 3.14.17, 3.15.12, 3.16.8 and 3.17.5 (vendor-report). These are historical remediation evidence, not current upgrade recommendations; the 3.17 documentation now marks that release series unsupported (vendor-release).

Award and evidence

USD 10,000Bug Bounty · Vendor Confirmed

One report award; cash receipt is unverified. USD is inferred from HackerOne’s platform-wide payment policy reviewed in October 2026, later than the August 2025 award; that context does not independently establish settlement.

Freshly read public GitHub summary and award/disclosure events in the cloud browser, plus GitHub release notes and HackerOne currency policy through web retrieval. Added bounded conceptual analysis without reproduction or testing.

  • Public report content supplies a vendor summary, not implementation-level patch details or a complete demonstration transcript.
  • GitHub.com deployment timing and exploitation-in-the-wild status are not established by the reviewed sources.
  • Release availability, report resolution and detailed publication have different dates.
  • Cash receipt is unverified; later platform-wide USD policy is contextual denomination evidence.

Recorded timeline

Published
2025-09-23explicit · Detailed report disclosure event, activity-37054322.
Public Disclosure
2025-08-25explicit · Vendor advisory in Enterprise Server 3.17.5 release notes preceded the detailed report.
Reported
2025-05-03explicit
Awarded
2025-08-26explicit
Fixed
2025-08-25explicit · Public GHES 3.17.5 release. Report Resolved status is August 26; GitHub.com deployment timing is not established.

Related visual models

Sources and provenance

  1. GitHub HackerOne report 3124517 GitHub security team and furbreeze · reviewed 2026-10-03
  2. GitHub Enterprise Server 3.17.5 release notes GitHub · reviewed 2026-10-03
  3. Vulnerability Disclosure Standards: Bug Bounty payment denomination HackerOne · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software