CVE-2023-23764
Summary
| CVE | CVE-2023-23764 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-27 21:15:00 UTC |
| Updated | 2023-08-03 15:39:00 UTC |
| Description | An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff within the GitHub pull request UI. To do so, an attacker would need write access to the repository. This vulnerability affected GitHub Enterprise Server versions 3.7.0 and above and was fixed in versions 3.7.9, 3.8.2, and 3.9.1. This vulnerability was reported via the GitHub Bug Bounty program. |
Risk And Classification
Problem Types: CWE-697
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Github | Enterprise Server | All | All | All | All |
| Application | Github | Enterprise Server | 3.9.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release notes - GitHub Enterprise Server 3.9 Docs | MISC | docs.github.com | |
| Release notes - GitHub Enterprise Server 3.7 Docs | MISC | docs.github.com | |
| Release notes - GitHub Enterprise Server 3.8 Docs | MISC | docs.github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.