CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS
Percentile
15.5%
An attacker with an Administrator role in GitHub Enterprise Server could gain SSH root access via remote code execution.Β This vulnerability affected GitHub Enterprise Server version 3.8.0 and above and was fixed in version 3.8.17, 3.9.12, 3.10.9, 3.11.7 and 3.12.1. This vulnerability was reported via the GitHub Bug Bounty program.
[
{
"defaultStatus": "affected",
"product": "Enterprise Server",
"vendor": "GitHub",
"versions": [
{
"changes": [
{
"at": "3.8.17",
"status": "unaffected"
}
],
"lessThanOrEqual": "3.8.16",
"status": "affected",
"version": "3.8.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.9.12",
"status": "unaffected"
}
],
"lessThanOrEqual": "3.9.11",
"status": "affected",
"version": "3.9.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.10.9",
"status": "unaffected"
}
],
"lessThanOrEqual": "3.10.8",
"status": "affected",
"version": "3.10.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.11.7",
"status": "unaffected"
}
],
"lessThanOrEqual": "3.11.6",
"status": "affected",
"version": "3.11.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.12.1",
"status": "unaffected"
}
],
"lessThanOrEqual": "3.12.0",
"status": "affected",
"version": "3.12",
"versionType": "semver"
}
]
}
]
docs.github.com/en/[email protected]/admin/release-notes#3.10.9
docs.github.com/en/[email protected]/admin/release-notes#3.11.7
docs.github.com/en/[email protected]/admin/release-notes#3.12.1
docs.github.com/en/[email protected]/admin/release-notes#3.8.17
docs.github.com/en/[email protected]/admin/release-notes#3.9.12