CVE-2024-0507
An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 65.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.11.3, 3.10.5, 3.9.8, and 3.8.13 This vulnerability was reported via the GitHub Bug Bounty program.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 65.80% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-77
- Affected
- github/enterprise server
- Source
- product-cna@github.com
References
- https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.5Release Notes
- https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.3Release Notes
- https://docs.github.com/en/enterprise-server@3.8/admin/release-notes#3.8.13Release Notes
- https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.8Release Notes
- https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.5Release Notes
- https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.3Release Notes
- https://docs.github.com/en/enterprise-server@3.8/admin/release-notes#3.8.13Release Notes
- https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.8Release Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.