Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-46649


A race condition in GitHub Enterprise Server was identified that could allow an attacker administrator access. To exploit this, an organization needs to be converted from a user. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.7.19, 3.8.12, 3.9.7, 3.10.4, and 3.11.1. 


Published

2023-12-21T21:15:09.573

Last Modified

2024-11-21T08:28:58.367

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-367
  • Type: Primary
    CWE-367

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application github enterprise_server < 3.7.19 Yes
Application github enterprise_server < 3.8.12 Yes
Application github enterprise_server < 3.9.7 Yes
Application github enterprise_server < 3.10.4 Yes
Application github enterprise_server 3.11.0 Yes

References