SB2024052332 - Insufficiently protected credentials in GitHub Desktop



SB2024052332 - Insufficiently protected credentials in GitHub Desktop

Published: May 23, 2024 Updated: September 25, 2026

Security Bulletin ID SB2024052332
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Insufficiently protected credentials (CVE-ID: N/A)

CWE-ID: CWE-522 - Insufficiently Protected Credentials

CVSSv4: 8.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose credentials.

The vulnerability exists due to improper credential handling in GitHub Desktop repository and submodule handling when processing repositories with submodules hosted on different hosts than the parent repository. A remote user can cause credentials to be transmitted to a different host to disclose credentials.

User interaction is required.


Remediation

Install update from vendor's website.