Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-23739


An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileges in GraphQL API requests from GitHub Apps. This vulnerability allowed an app installed on an organization to gain access to and modify most organization-level resources that are not tied to a repository regardless of granted permissions, such as users and organization-wide projects. Resources associated with repositories were not impacted, such as repository file content, repository-specific projects, issues, or pull requests. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.7.1 and was fixed in versions 3.3.16, 3.4.11, 3.5.8, 3.6.4, 3.7.1. This vulnerability was reported via the GitHub Bug Bounty program.


Published

2023-01-17T19:15:11.340

Last Modified

2025-04-08T21:15:44.423

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-863
  • Type: Primary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application github enterprise_server < 3.3.16 Yes
Application github enterprise_server < 3.4.11 Yes
Application github enterprise_server < 3.5.8 Yes
Application github enterprise_server < 3.6.4 Yes
Application github enterprise_server 3.7.0 Yes

References