CVE-2023-6803

MEDIUM

GitHub Enterprise Server 3.8.0-3.8.11 - Time-of-check Time-of-use Race Condition

Title source: llm
STIX 2.1

Description

A race condition in GitHub Enterprise Server allows an outside collaborator to be added while a repository is being transferred. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.

Scores

CVSS v3 5.8
EPSS 0.0017
EPSS Percentile 6.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L

Details

CWE
CWE-367
Status published
Products (2)
github/enterprise_server 3.11.0
github/enterprise_server 3.8.0 - 3.8.12
Published Dec 21, 2023
Tracked Since Feb 18, 2026