High severity7.5NVD Advisory· Published Apr 5, 2012· Updated Apr 29, 2026
CVE-2012-2055
CVE-2012-2055
Description
GitHub Enterprise before 20120304 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the public_key[user_id] value via a modified URL for the public-key update form, related to a "mass assignment" vulnerability.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- lwn.net/Articles/488702/nvdThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/74812nvdThird Party AdvisoryVDB Entry
- homakov.blogspot.com/2012/03/how-to.htmlnvdIssue Tracking
News mentions
0No linked articles in our index yet.