CVE-2023-6804 MEDIUM

CVE-2023-6804: Improper Privilege Management allows for arbitrary workflows to be run

Vendor Github
Product Enterprise Server
Weakness CWE-269
Published December 21, 2023
Last update November 27, 2024

CVSS base score

6.5/10
Attack vector Local
Attack complexity High
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L

What the vulnerability does

01Description

Improper privilege management allowed arbitrary workflows to be committed and run using an improperly scoped PAT. To exploit this, a workflow must have already existed in the target repo. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.

Key dates

02Disclosure timeline

December 21, 2023 CVE published
November 27, 2024 Record updated