← volver
CVE-2024-0507mediumCWE-20

Privilege Escalation by Code Injection in the Management Console in GitHub Enterprise Server

25Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 6.5epss 66%
probabilidad de explotación
66%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.11.3, 3.10.5, 3.9.8, and 3.8.13 This vulnerability was reported via the GitHub Bug Bounty program.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Productos afectados
GitHub · Enterprise Server