PT-2022-16239 · Github · Github Enterprise Server
Alex Chapman
·
Published
2022-10-19
·
Updated
2025-05-09
·
CVE-2022-23734
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GitHub Enterprise Server versions prior to 3.6
GitHub Enterprise Server version 3.5.3
GitHub Enterprise Server version 3.4.6
GitHub Enterprise Server version 3.3.11
GitHub Enterprise Server version 3.2.16
Description
A deserialization of untrusted data issue was identified that could potentially lead to remote code execution on the SVNBridge. To exploit this, an attacker would need to gain access via a server-side request forgery (SSRF) that would let an attacker control the data being deserialized. This issue was reported via the GitHub Bug Bounty program.
Recommendations
For versions prior to 3.6, update to version 3.6 or later to resolve the issue.
For version 3.5.3, no additional action is required as this version contains a fix.
For version 3.4.6, no additional action is required as this version contains a fix.
For version 3.3.11, no additional action is required as this version contains a fix.
For version 3.2.16, no additional action is required as this version contains a fix.
As a temporary workaround, consider restricting access to the SVNBridge to minimize the risk of exploitation.
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Github Enterprise Server