← Back

CVE-2023-46647

nvd nist
Published: Dec 21, 2023Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Improper privilege management in all versions of GitHub Enterprise Server allows users with authorized access to the management console with an editor role to escalate their privileges by making requests to the endpoint used for bootstrapping the instance. This vulnerability affected GitHub Enterprise Server version 3.8.0 and above and was fixed in version 3.8.12, 3.9.6, 3.10.3, and 3.11.0.

Affected (3)

1 product
Enterprise Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Github
From 3.10.0 to 3.10.3
From 3.8.0 to 3.8.12
From 3.9.0 to 3.9.6

References (8)

Timeline

No history available yet.