logoalt Hacker News

brianmcnultyyesterday at 6:45 PM1 replyview on HN

I assume a fair amount of these on-prem customers restrict access to their GHES instance to be behind corporate VPN or something similar and are planning a date to upgrade their instance that won't affect operations.

Any public instance should update immediately though, it's not very hard to put together how to repro the vulnerability on your own from what they provide in the article and the fact that GitHub Enterprise source is publicly available.


Replies

jamesfinlaysontoday at 12:25 AM

For sure - the last company I worked at that had GitHub Enterprise had it running on a private network only accessible within the company.

show 1 reply