CVE-2024-0507
MEDIUMGitHub Enterprise Server - Privilege Escalation
Title source: llmDescription
An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.11.3, 3.10.5, 3.9.8, and 3.8.13 This vulnerability was reported via the GitHub Bug Bounty program.
Exploits (1)
nomisec
WORKING POC
by convisolabs · poc
https://github.com/convisolabs/CVE-2024-0507_CVE-2024-0200-github
References (4)
Scores
CVSS v3
6.5
EPSS
0.7288
EPSS Percentile
98.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Details
CWE
CWE-20
CWE-77
Status
published
Products (1)
github/enterprise_server
< 3.8.13
Published
Jan 16, 2024
Tracked Since
Feb 18, 2026