CVE-2022-23737
Published on: Not Yet Published
Last Modified on: 12/05/2022 03:23:00 PM UTC
Certain versions of Enterprise Server from Github contain the following vulnerability:
An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privileges to create or delete pages via the API. To exploit this vulnerability, an attacker would need to be added to an organization's repo with write permissions. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.7 and was fixed in versions 3.2.20, 3.3.15, 3.4.10, 3.5.7, and 3.6.3. This vulnerability was reported via the GitHub Bug Bounty program.
- CVE-2022-23737 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
GitHub - GitHub Enterprise Server version < 3.2.20
- Affected Vendor/Software:
GitHub - GitHub Enterprise Server version < 3.3.15
- Affected Vendor/Software:
GitHub - GitHub Enterprise Server version < 3.4.10
- Affected Vendor/Software:
GitHub - GitHub Enterprise Server version < 3.5.7
- Affected Vendor/Software:
GitHub - GitHub Enterprise Server version < 3.6.3
CVSS3 Score: 6.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | HIGH | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Release notes - GitHub Enterprise Server 3.3 Docs | docs.github.com text/html |
![]() |
Release notes - GitHub Enterprise Server 3.5 Docs | docs.github.com text/html |
![]() |
Release notes - GitHub Enterprise Server 3.2 Docs | docs.github.com text/html |
![]() |
Release notes - GitHub Enterprise Server 3.6 Docs | docs.github.com text/html |
![]() |
Release notes - GitHub Enterprise Server 3.4 Docs | docs.github.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Github | Enterprise Server | All | All | All | All |
- cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*:
Discovery Credit
Ali Shehab and Ali Kalout
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-23737 : An improper privilege management vulnerability was identified in GitHub Enterprise Server that all… twitter.com/i/web/status/1… | 2022-12-01 21:17:13 |
![]() |
New vulnerability on the NVD: CVE-2022-23737 ift.tt/ayge2Nw | 2022-12-01 23:14:59 |
![]() |
CVE-2022-23737 ift.tt/YurDNZI | 2022-12-01 23:24:33 |
![]() |
CVE-2022-23737 | 2022-12-01 22:19:00 |