Remote Code Execution Vulnerability Affects GitHub Enterprise Server
CVE-2024-2469

8HIGH

Key Information:

Vendor
Github
Vendor
CVE Published:
20 March 2024

Summary

A vulnerability exists within GitHub Enterprise Server that allows attackers with Administrator privileges to execute arbitrary code remotely, leading to potential SSH root access. This serious security flaw affects versions 3.8.0 and above of GitHub Enterprise Server. It was reported through the GitHub Bug Bounty program and has been addressed in the following patched versions: 3.8.17, 3.9.12, 3.10.9, 3.11.7, and 3.12.1. Organizations using affected versions are strongly encouraged to update to secure their environments against this exploitation vector.

Affected Version(s)

Enterprise Server 3.8.0 <= 3.8.16

Enterprise Server 3.8.0 <= 3.8.16

Enterprise Server 3.9.0 <= 3.9.11

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

inspector-ambitious
.