Insufficient Entropy in GitHub Enterprise Server Management Console Invitation Token
CVE-2023-46648

8.3HIGH

Key Information:

Vendor
GitHub
Vendor
CVE Published:
21 December 2023

Summary

A security vulnerability was found in GitHub Enterprise Server that allows attackers to brute-force a pending user invitation to the Management Console. To exploit this vulnerability, an attacker must be aware of the existence of an invitation. This affects all versions of GitHub Enterprise Server from 3.8 to prior versions of 3.8.12, 3.9.7, 3.10.4, and 3.11.1, where security patches have been implemented.

Affected Version(s)

Enterprise Server 3.8.0 < 3.8.12

Enterprise Server 3.9.0 < 3.9.7

Enterprise Server 3.10.0 < 3.10.4

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Imre Rad
.