CVE-2024-0200
HIGH NUCLEIGitHub Enterprise Server 3.8.0-3.8.12 - Authenticated Remote Code Execution via Unsafe Reflection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-0200. PoCs published by convisolabs. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2024-0200, leveraging unsafe reflection to leak the ENTERPRISE_SESSION_SECRET and achieve remote code execution via Marshal deserialization in GitHub Enterprise Server.
Description
An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead to the execution of user-controlled methods and remote code execution. To exploit this bug, an actor would need to be logged into an account on the GHES instance with the organization owner role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.8.13, 3.9.8, 3.10.5, and 3.11.3. This vulnerability was reported via the GitHub Bug Bounty program.
Exploits (1)
This repository contains a functional exploit for CVE-2024-0200, leveraging unsafe reflection to leak the ENTERPRISE_SESSION_SECRET and achieve remote code execution via Marshal deserialization in GitHub Enterprise Server.
Nuclei Templates (1)
title:"GitHub Enterprise" || micro focus dsd
app="Github-Enterprise"
References (4)
Scores
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L