CVE-2024-0507

MEDIUM

GitHub Enterprise Server - Privilege Escalation

Title source: llm

Description

An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.11.3, 3.10.5, 3.9.8, and 3.8.13 This vulnerability was reported via the GitHub Bug Bounty program.

Exploits (1)

nomisec WORKING POC
by convisolabs · poc
https://github.com/convisolabs/CVE-2024-0507_CVE-2024-0200-github

Scores

CVSS v3 6.5
EPSS 0.7288
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-20 CWE-77
Status published
Products (1)
github/enterprise_server < 3.8.13
Published Jan 16, 2024
Tracked Since Feb 18, 2026