Improper Privilege Management allows for arbitrary workflows to be run

CVE-2023-6804
6.5MEDIUM

Key Information

Vendor
GitHub
Status
Enterprise Server
Vendor
CVE Published:
21 December 2023

Summary

Improper privilege management allowed arbitrary workflows to be committed and run using an improperly scoped PAT. To exploit this, a workflow must have already existed in the target repo. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.

Affected Version(s)

Enterprise Server <= 3.8.11

Enterprise Server <= 3.8.11

Enterprise Server <= 3.9.6

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.