← back
CVE-2024-2469highCWE-20

Remote Code Execution in GitHub Enterprise Server Allowed Administrators to gain SSH access to the appliance

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8epss 1.6%
exploitation probability
1.6%top 26% of all CVEs
observed exploitation
nono source reports it
An attacker with an Administrator role in GitHub Enterprise Server could gain SSH root access via remote code execution. This vulnerability affected GitHub Enterprise Server version 3.8.0 and above and was fixed in version 3.8.17, 3.9.12, 3.10.9, 3.11.7 and 3.12.1. This vulnerability was reported via the GitHub Bug Bounty program.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H