PT-2022-27794 · Github · Github Enterprise Server

Yvvdwf

·

Published

2022-12-14

·

Updated

2022-12-16

·

CVE-2022-46255

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitHub Enterprise Server version 3.7.0
Description An improper limitation of a pathname to a restricted directory was identified, enabling remote code execution. A check was added within Pages to ensure the working directory is clean before unpacking new content, preventing an arbitrary file overwrite bug. This issue was reported via the GitHub Bug Bounty program.
Recommendations For version 3.7.0, update to version 3.7.1 to resolve the issue. As a temporary workaround, consider ensuring the working directory is clean before unpacking new content to prevent arbitrary file overwrites.

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-46255

Affected Products

Github Enterprise Server