PT-2022-16237 · Github · Github Enterprise Server

Bitquark

·

Published

2022-04-05

·

Updated

2022-04-13

·

CVE-2022-23732

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitHub Enterprise Server versions prior to 3.5
Description A path traversal issue was identified in the management console, allowing the bypass of CSRF protections, which could lead to privilege escalation. An attacker would need to target a user actively logged into the management console to exploit this issue.
Recommendations For versions prior to 3.1.19, update to version 3.1.19 or later. For versions prior to 3.2.11, update to version 3.2.11 or later. For versions prior to 3.3.6, update to version 3.3.6 or later. For versions prior to 3.4.1, update to version 3.4.1 or later.

Fix

Path traversal

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23732

Affected Products

Github Enterprise Server