PT-2022-16240 · Github · Github Enterprise Server
Published
2022-12-01
·
Updated
2025-04-24
·
CVE-2022-23737
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
GitHub Enterprise Server versions prior to 3.7
Description
An improper privilege management issue was identified that allowed users with improper privileges to create or delete pages via the API. To exploit this, an attacker would need to be added to an organization's repo with write permissions. This issue was reported via the GitHub Bug Bounty program.
Recommendations
For versions prior to 3.2.20, update to version 3.2.20 or later.
For versions prior to 3.3.15, update to version 3.3.15 or later.
For versions prior to 3.4.10, update to version 3.4.10 or later.
For versions prior to 3.5.7, update to version 3.5.7 or later.
For versions prior to 3.6.3, update to version 3.6.3 or later.
As a temporary workaround, consider restricting access to the API for users with write permissions until a patch is applied.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Github Enterprise Server