PT-2022-16244 · Github · Github Enterprise Server

Vaibhav Singh

·

Published

2022-12-14

·

Updated

2022-12-16

·

CVE-2022-23741

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitHub Enterprise Server versions prior to 3.3.17 GitHub Enterprise Server versions prior to 3.4.12 GitHub Enterprise Server versions prior to 3.5.9 GitHub Enterprise Server versions prior to 3.6.5
Description An incorrect authorization issue was identified in GitHub Enterprise Server, allowing a scoped user-to-server token to escalate to full admin/owner privileges. An attacker would require an account with admin access to install a malicious GitHub App. This issue was reported via the GitHub Bug Bounty program.
Recommendations For versions prior to 3.3.17, update to version 3.3.17 or later. For versions prior to 3.4.12, update to version 3.4.12 or later. For versions prior to 3.5.9, update to version 3.5.9 or later. For versions prior to 3.6.5, update to version 3.6.5 or later.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-23741

Affected Products

Github Enterprise Server