CVE-2024-0507

An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.11.3, 3.10.5, 3.9.8, and 3.8.13 This vulnerability was reported via the GitHub Bug Bounty program.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
GitHub_PCNA
6.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
githubenterprise_server
3.8.12 ≤
𝑥
≤ 3.8.12
githubenterprise_server
3.9.7 ≤
𝑥
≤ 3.9.7
githubenterprise_server
3.10.4 ≤
𝑥
≤ 3.10.4
githubenterprise_server
3.11.2 ≤
𝑥
≤ 3.11.2
githubenterprise_server
𝑥
< 3.8.13
githubenterprise_server
3.9.0 ≤
𝑥
< 3.9.8
githubenterprise_server
3.10.0 ≤
𝑥
< 3.10.5
githubenterprise_server
3.11.0 ≤
𝑥
< 3.11.3
𝑥
= Vulnerable software versions