{"api_version":"1","generated_at":"2026-07-23T21:42:30+00:00","cve":"CVE-2022-23733","urls":{"html":"https://cve.report/CVE-2022-23733","api":"https://cve.report/api/cve/CVE-2022-23733.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-23733","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-23733"},"summary":{"title":"CVE-2022-23733","description":"A stored XSS vulnerability was identified in GitHub Enterprise Server that allowed the injection of arbitrary attributes. This injection was blocked by Github's Content Security Policy (CSP). This vulnerability affected all versions of GitHub Enterprise Server prior to 3.6 and was fixed in versions 3.3.11, 3.4.6 and 3.5.3. This vulnerability was reported via the GitHub Bug Bounty program.","state":"PUBLIC","assigner":"product-cna@github.com","published_at":"2022-08-02 16:15:00","updated_at":"2023-11-07 03:44:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://docs.github.com/en/enterprise-server%403.4/admin/release-notes#3.4.6","name":"https://docs.github.com/en/enterprise-server%403.4/admin/release-notes#3.4.6","refsource":"","tags":[],"title":"Release notes - GitHub Enterprise Server 3.4 Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.github.com/en/enterprise-server@3.3/admin/release-notes#3.3.11","name":"N/A","refsource":"CONFIRM","tags":[],"title":"Release notes - GitHub Enterprise Server 3.3 Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.github.com/en/enterprise-server%403.3/admin/release-notes#3.3.11","name":"https://docs.github.com/en/enterprise-server%403.3/admin/release-notes#3.3.11","refsource":"","tags":[],"title":"Release notes - GitHub Enterprise Server 3.3 Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.github.com/en/enterprise-server%403.5/admin/release-notes#3.5.3","name":"https://docs.github.com/en/enterprise-server%403.5/admin/release-notes#3.5.3","refsource":"","tags":[],"title":"Release notes - GitHub Enterprise Server 3.5 Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.github.com/en/enterprise-server@3.5/admin/release-notes#3.5.3","name":"N/A","refsource":"CONFIRM","tags":[],"title":"Release notes - GitHub Enterprise Server 3.5 Docs","mime":"text/html","httpstatus":"200","archivestatus":"403"},{"url":"https://docs.github.com/en/enterprise-server@3.4/admin/release-notes#3.4.6","name":"N/A","refsource":"CONFIRM","tags":[],"title":"Release notes - GitHub Enterprise Server 3.4 Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-23733","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23733","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"None","lang":""}],"nvd_cpes":[{"cve_year":"2022","cve_id":"23733","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"github","cpe5":"enterprise_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"product-cna@github.com","ID":"CVE-2022-23733","STATE":"PUBLIC","TITLE":"Stored XSS vulnerability in GitHub Enterprise Server leading to injection of arbitrary attributes"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"GitHub Enterprise Server","version":{"version_data":[{"version_affected":"<","version_name":"3.3","version_value":"3.3.11"},{"version_affected":"<","version_name":"3.4","version_value":"3.4.6"},{"version_affected":"<","version_name":"3.5","version_value":"3.5.3"}]}}]},"vendor_name":"GitHub"}]}},"credit":[{"lang":"eng","value":"None"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A stored XSS vulnerability was identified in GitHub Enterprise Server that allowed the injection of arbitrary attributes. This injection was blocked by Github's Content Security Policy (CSP). This vulnerability affected all versions of GitHub Enterprise Server prior to 3.6 and was fixed in versions 3.3.11, 3.4.6 and 3.5.3. This vulnerability was reported via the GitHub Bug Bounty program."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-79 Cross-site Scripting (XSS) - Stored"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://docs.github.com/en/enterprise-server@3.3/admin/release-notes#3.3.11","name":"https://docs.github.com/en/enterprise-server@3.3/admin/release-notes#3.3.11"},{"refsource":"MISC","url":"https://docs.github.com/en/enterprise-server@3.4/admin/release-notes#3.4.6","name":"https://docs.github.com/en/enterprise-server@3.4/admin/release-notes#3.4.6"},{"refsource":"MISC","url":"https://docs.github.com/en/enterprise-server@3.5/admin/release-notes#3.5.3","name":"https://docs.github.com/en/enterprise-server@3.5/admin/release-notes#3.5.3"}]},"source":{"discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2022-08-02 16:15:00","lastModifiedDate":"2023-11-07 03:44:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5.0","versionEndExcluding":"3.5.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4.0","versionEndExcluding":"3.4.6","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*","versionStartIncluding":"3.3.0","versionEndExcluding":"3.3.11","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2022","CveId":"23733","Ordinal":"226595","Title":"CVE-2022-23733","CVE":"CVE-2022-23733","Year":"2022"},"notes":[{"CveYear":"2022","CveId":"23733","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}