CVE-2022-23734
Published on: Not Yet Published
Last Modified on: 10/20/2022 07:40:00 PM UTC
Certain versions of Enterprise Server from Github contain the following vulnerability:
A deserialization of untrusted data vulnerability was identified in GitHub Enterprise Server that could potentially lead to remote code execution on the SVNBridge. To exploit this vulnerability, an attacker would need to gain access via a server-side request forgery (SSRF) that would let an attacker control the data being deserialized. This vulnerability affected all versions of GitHub Enterprise Server prior to v3.6 and was fixed in versions 3.5.3, 3.4.6, 3.3.11, and 3.2.16. This vulnerability was reported via the GitHub Bug Bounty program.
- CVE-2022-23734 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
GitHub - GitHub Enterprise Server version < 3.2.16
- Affected Vendor/Software:
GitHub - GitHub Enterprise Server version < 3.3.11
- Affected Vendor/Software:
GitHub - GitHub Enterprise Server version < 3.4.6
- Affected Vendor/Software:
GitHub - GitHub Enterprise Server version < 3.5.3
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Release notes - GitHub Enterprise Server 3.2 Docs | docs.github.com text/html |
![]() |
Release notes - GitHub Enterprise Server 3.3 Docs | docs.github.com text/html |
![]() |
Release notes - GitHub Enterprise Server 3.5 Docs | docs.github.com text/html |
![]() |
Release notes - GitHub Enterprise Server 3.4 Docs | docs.github.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Github | Enterprise Server | All | All | All | All |
- cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*:
Discovery Credit
Alex Chapman
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-23734 : A deserialization of untrusted data vulnerability was identified in GitHub Enterprise Server that… twitter.com/i/web/status/1… | 2022-10-19 14:14:56 |
![]() |
CVE-2022-23734 | 2022-10-19 14:39:10 |