Improper Privilege Management allows for arbitrary workflows to be run
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 0.2%
exploitation probability
0.2%top 89% of all CVEs
observed exploitation
nono source reports it
Improper privilege management allowed arbitrary workflows to be committed and run using an improperly scoped PAT. To exploit this, a workflow must have already existed in the target repo. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Affected products
GitHub · Enterprise ServerReferences
https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.4https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.1https://docs.github.com/en/enterprise-server@3.8/admin/release-notes#3.8.12https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.7