← Back

CVE-2023-6746

nvd nist
Published: Dec 21, 2023Modified: Jun 17, 2026

JSON object

Loading...
5.7
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
Exploitability: 0.5 / Impact: 5.2
Source: NVD

Description

An insertion of sensitive information into log file vulnerability was identified in the log files for a GitHub Enterprise Server back-end service that could permit an `adversary in the middle attack` when combined with other phishing techniques. To exploit this, an attacker would need access to the log files for the GitHub Enterprise Server appliance, a backup archive created with GitHub Enterprise Server Backup Utilities, or a service which received streamed logs. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.7.19, 3.8.12, 3.9.7, 3.10.4, and 3.11.1. 

Affected (5)

1 product
Enterprise Server
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Github
From 3.10.0 to 3.10.4
From 3.7.0 to 3.7.19
From 3.8.0 to 3.8.12
From 3.9.0 to 3.9.7
Version 3.11.0

References (10)

Timeline

No history available yet.