CVE-2022-23741
HIGHGitHub Enterprise Server < 3.3.17 - Incorrect Authorization via Scoped User-to-Server Token
Title source: llmDescription
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a scoped user-to-server token to escalate to full admin/owner privileges. An attacker would require an account with admin access to install a malicious GitHub App. This vulnerability was fixed in versions 3.3.17, 3.4.12, 3.5.9, and 3.6.5. This vulnerability was reported via the GitHub Bug Bounty program.
References (4)
Core 4
Core References
Scores
CVSS v3
7.2
EPSS
0.0110
EPSS Percentile
61.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-863
Status
published
Products (1)
github/enterprise_server
< 3.3.17
Published
Dec 14, 2022
Tracked Since
Feb 18, 2026