Remote Code Execution Vulnerability Affects GitHub Enterprise Server
CVE-2024-2469
8HIGH
Summary
A vulnerability exists within GitHub Enterprise Server that allows attackers with Administrator privileges to execute arbitrary code remotely, leading to potential SSH root access. This serious security flaw affects versions 3.8.0 and above of GitHub Enterprise Server. It was reported through the GitHub Bug Bounty program and has been addressed in the following patched versions: 3.8.17, 3.9.12, 3.10.9, 3.11.7, and 3.12.1. Organizations using affected versions are strongly encouraged to update to secure their environments against this exploitation vector.
Affected Version(s)
Enterprise Server 3.8.0 <= 3.8.16
Enterprise Server 3.8.0 <= 3.8.16
Enterprise Server 3.9.0 <= 3.9.11
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
inspector-ambitious