CVE
- Id
- 55298
- CVE No.
- CVE-2012-2055
- Status
- Candidate
- Description
- GitHub Enterprise before 20120304 does not properly restrict the use of a hash to provide values for a model"s attributes, which allows remote attackers to set the public_key[user_id] value via a modified URL for the public-key update form, related to a "mass assignment" vulnerability.
- Phase
- Assigned (20120404)
- Votes
- None (candidate not yet proposed)
- Comments