CVE-2023-6690
2.0
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N
Exploitability: 0.5 / Impact: 1.4
Source: NVD
Description
A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphQL mutation to alter repository permissions during the transfer. This vulnerability affected GitHub Enterprise Server version 3.8.0 and above and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.
Affected (4)
Products: Github: Enterprise Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.10.0 to 3.10.4 |
References (8)
Source: product-cna@github.com
Release Notes
Source: product-cna@github.com
Release Notes
Source: product-cna@github.com
Release Notes
Source: product-cna@github.com
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Timeline
No history available yet.