PT-2022-16239 · Github · Github Enterprise Server

Alex Chapman

·

Published

2022-10-19

·

Updated

2025-05-09

·

CVE-2022-23734

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitHub Enterprise Server versions prior to 3.6 GitHub Enterprise Server version 3.5.3 GitHub Enterprise Server version 3.4.6 GitHub Enterprise Server version 3.3.11 GitHub Enterprise Server version 3.2.16
Description A deserialization of untrusted data issue was identified that could potentially lead to remote code execution on the SVNBridge. To exploit this, an attacker would need to gain access via a server-side request forgery (SSRF) that would let an attacker control the data being deserialized. This issue was reported via the GitHub Bug Bounty program.
Recommendations For versions prior to 3.6, update to version 3.6 or later to resolve the issue. For version 3.5.3, no additional action is required as this version contains a fix. For version 3.4.6, no additional action is required as this version contains a fix. For version 3.3.11, no additional action is required as this version contains a fix. For version 3.2.16, no additional action is required as this version contains a fix. As a temporary workaround, consider restricting access to the SVNBridge to minimize the risk of exploitation.

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2022-23734

Affected Products

Github Enterprise Server