CVE-2023-6804
MEDIUMGitHub Enterprise Server 3.8.0-3.8.11 - Improper Privilege Management via Workflow Commit with Improperly Scoped PAT
Title source: llmDescription
Improper privilege management allowed arbitrary workflows to be committed and run using an improperly scoped PAT. To exploit this, a workflow must have already existed in the target repo. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.
References (4)
Core 4
Core References
Scores
CVSS v3
6.5
EPSS
0.0020
EPSS Percentile
10.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-269
Status
published
Products (2)
github/enterprise_server
3.11.0
github/enterprise_server
3.8.0 - 3.8.12
Published
Dec 21, 2023
Tracked Since
Feb 18, 2026