CVE-2023-6804

I

mproper privilege management allowed arbitrary workflows to be committed and run using an improperly scoped PAT. To exploit this, a workflow must have already existed in the target repo. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
cpe:2.3:a:github:enterprise_server:3.11.0:*:*:*:*:*:*:*

History

21 Nov 2024, 08:44

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 6.5
References () https://docs.github.com/en/[email protected]/admin/release-notes#3.10.4 - Release Notes () https://docs.github.com/en/[email protected]/admin/release-notes#3.10.4 - Release Notes
References () https://docs.github.com/en/[email protected]/admin/release-notes#3.11.1 - Release Notes () https://docs.github.com/en/[email protected]/admin/release-notes#3.11.1 - Release Notes
References () https://docs.github.com/en/[email protected]/admin/release-notes#3.8.12 - Release Notes () https://docs.github.com/en/[email protected]/admin/release-notes#3.8.12 - Release Notes
References () https://docs.github.com/en/[email protected]/admin/release-notes#3.9.7 - Release Notes () https://docs.github.com/en/[email protected]/admin/release-notes#3.9.7 - Release Notes

Information

Published : 2023-12-21 21:15

Updated : 2024-11-21 08:44


NVD link : CVE-2023-6804

Mitre link : CVE-2023-6804

CVE.ORG link : CVE-2023-6804


JSON object : View

Products Affected
CWE
CWE-269

Improper Privilege Management