CVE-2023-46647

HIGH

GitHub Enterprise Server <3.8.12 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Improper privilege management in all versions of GitHub Enterprise Server allows users with authorized access to the management console with an editor role to escalate their privileges by making requests to the endpoint used for bootstrapping the instance. This vulnerability affected GitHub Enterprise Server version 3.8.0 and above and was fixed in version 3.8.12, 3.9.6, 3.10.3, and 3.11.0.

Scores

CVSS v3 8.0
EPSS 0.0064
EPSS Percentile 45.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (1)
github/enterprise_server 3.8.0 - 3.8.12
Published Dec 21, 2023
Tracked Since Feb 18, 2026