CVE Published: 14/12/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: GitHub_P |
Vendor: GitHub |
Product: GitHub Enterprise Server Status : PUBLISHED
CVE-2022-23741 Description
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a scoped user-to-server token to escalate to full admin/owner privileges. An attacker would require an account with admin access to install a malicious GitHub App. This vulnerability was fixed in versions 3.3.17, 3.4.12, 3.5.9, and 3.6.5. This vulnerability was reported via the GitHub Bug Bounty program.