CVE-2022-23741

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a scoped user-to-server token to escalate to full admin/owner privileges. An attacker would require an account with admin access to install a malicious GitHub App. This vulnerability was fixed in versions 3.3.17, 3.4.12, 3.5.9, and 3.6.5. This vulnerability was reported via the GitHub Bug Bounty program.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GitHub_PCNA
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
Affected Products (NVD)
VendorProductVersion
githubenterprise_server
𝑥
< 3.3.17
githubenterprise_server
3.4.0 ≤
𝑥
< 3.4.12
githubenterprise_server
3.5.0 ≤
𝑥
< 3.5.9
githubenterprise_server
3.6.0 ≤
𝑥
< 3.6.5
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
githubgithub
3.3 ≤
𝑥
< 3.3.17
CNA
githubgithub
3.4 ≤
𝑥
< 3.4.12
CNA
githubgithub
3.5 ≤
𝑥
< 3.5.9
CNA
githubgithub
3.6 ≤
𝑥
< 3.6.5
CNA