Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wmc3-gvp9-38qp

Опубликовано: 16 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.11.3, 3.10.5, 3.9.8, and 3.8.13 This vulnerability was reported via the GitHub Bug Bounty program.

An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.11.3, 3.10.5, 3.9.8, and 3.8.13 This vulnerability was reported via the GitHub Bug Bounty program.

EPSS

Процентиль: 99%
0.73942
Высокий

6.5 Medium

CVSS3

Дефекты

CWE-20
CWE-77

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 лет назад

An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.11.3, 3.10.5, 3.9.8, and 3.8.13 This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 6.5
fstec
около 2 лет назад

Уязвимость консоли управления (Management Consol) корпоративной версии платформы GitHub Enterprise Server, позволяющая нарушителю выполнить произвольные команды и повысить свои привилегии

EPSS

Процентиль: 99%
0.73942
Высокий

6.5 Medium

CVSS3

Дефекты

CWE-20
CWE-77