GitHub Enterprise Server's notebook viewer can lead a network caller from blind SSRF to appliance code execution.
GitHub Enterprise Server, self-hosted source-code collaboration appliances; unauthenticated exposure applies when private mode is disabled.
Unsafe handling of an explicit URL port permits blind SSRF to co-located services. A timing oracle can recover appliance secrets, which are then used in a separate internal interaction to execute code.
Detail and 5 sources
The route is anonymous when private mode is off and otherwise requires an ordinary account. Fixed releases are available, but the affected population reaches end-of-life hardware.