Race Condition was identified in GitHub Enterprise Server that allowed maintaining admin permissions
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.5epss 0.5%
probabilidad de explotación
0.5%top 63% de las CVE
explotación observada
noninguna fuente lo reporta
A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on a detached repository by making a GraphQL mutation to alter repository permissions while the repository is detached. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.13 and was fixed in versions 3.9.13, 3.10.10, 3.11.8 and 3.12.1. This vulnerability was reported via the GitHub Bug Bounty program.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:L
Productos afectados
GitHub · Enterprise ServerReferencias
https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.10https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.8https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.2https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.13