CVE-2023-46649
MEDIUMGitHub Enterprise Server <3.7.19-3.11.1 - Privilege Escalation
Title source: llmDescription
A race condition in GitHub Enterprise Server was identified that could allow an attacker administrator access. To exploit this, an organization needs to be converted from a user. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.7.19, 3.8.12, 3.9.7, 3.10.4, and 3.11.1.
References (5)
Core 5
Core References
Scores
CVSS v3
6.3
EPSS
0.0017
EPSS Percentile
7.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-367
Status
published
Products (2)
github/enterprise_server
3.11.0
github/enterprise_server
3.7.0 - 3.7.19
Published
Dec 21, 2023
Tracked Since
Feb 18, 2026