CVE-2023-46649

MEDIUM

GitHub Enterprise Server <3.7.19-3.11.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A race condition in GitHub Enterprise Server was identified that could allow an attacker administrator access. To exploit this, an organization needs to be converted from a user. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.7.19, 3.8.12, 3.9.7, 3.10.4, and 3.11.1. 

Scores

CVSS v3 6.3
EPSS 0.0017
EPSS Percentile 7.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-367
Status published
Products (2)
github/enterprise_server 3.11.0
github/enterprise_server 3.7.0 - 3.7.19
Published Dec 21, 2023
Tracked Since Feb 18, 2026