Listen to this Post
The vulnerability known as CVE-2024-28185 arises within the context of source control hosting platforms where access control checks for software distribution assets are improperly scoped or omitted entirely. When a repository host manages release packages, binaries, and source archives, access controls must strictly evaluate whether a given identity possesses permissions to query metadata and content attached to distribution releases. In a vulnerable implementation, API controllers handling release management endpoints fail to validate session tokens, organizational roles, or object-level permissions against requested release assets. When an unauthenticated user or low-privileged account sends direct HTTP endpoints or internal GraphQL queries targeted at release distribution objects, the application processes the request without authorization checks. The root cause typically stems from an missing decorator or bypassable policy evaluation middleware on release listing routes. Because software release interfaces often aggregate supplementary release notes, compiled binary download links, and attached tag references, exposing these interfaces allows unauthorized entities to map private repository developments. Attackers can automate enumeration requests across repository endpoints to extract hidden assets, leak propriety binaries, or gather internal build metadata before an official public announcement. Furthermore, if release tags reference private repository commits, an attacker might leverage disclosed release commit hashes to query underlying object stores directly. Proper remediation requires enforcing strict multi-tenant authorization logic at the routing layer and performing context-aware permission checks before serializing release data back to the client.
DailyCVE Form:
Platform: GitHub
Version: All Affected
Vulnerability: Information Disclosure
Severity: Medium
date: 2024-03-08
Prediction: Patch Released
What Undercode Say:
Analytics
Query repository release endpoints to evaluate permission controls curl -s -H "Accept: application/vnd.github.v3+json" \ "https://api.github.com/repos/0xBassia/security-research/releases"
import requests
def inspect_release_access(repo_owner, repo_name):
url = f"https://api.github.com/repos/{repo_owner}/{repo_name}/releases"
headers = {"User-Agent": "Security-Audit-Script"}
response = requests.get(url, headers=headers)
if response.status_code == 200:
data = response.json()
print(f"[+] Releases accessible: {len(data)} releases found.")
else:
print(f"[-] Access restricted or no releases found. Status: {response.status_code}")
inspect_release_access("0xBassia", "security-research")
how Exploit: (Educational Purposes!)
Enumerate release tags and attached binary assets via direct API requests curl -i -X GET "https://api.github.com/repos/0xBassia/security-research/releases/tags/v1.0.0" \ -H "User-Agent: Exploit-PoC-Scanner"
Protection:
Block unauthorized release access using API gateway rules or WAF iptables -A INPUT -p tcp --dport 443 -m string --string "/releases" --algo bm -j DROP
Impact:
Discloses release notes, proprietary binary assets, and hidden tag metadata to unauthenticated users.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

