Lucene search

K
hackeroneBitquarkH1:1497169
HistoryMar 02, 2022 - 2:02 a.m.

GitHub: CSRF protection bypass in GitHub Enterprise management console

2022-03-0202:02:11
bitquark
hackerone.com
$10000
28
github enterprise
path traversal
csrf protections
privilege escalation
user targeting
management console
vulnerability
github enterprise server
cve-2022-23732
bug bounty

EPSS

0.002

Percentile

56.0%

A path traversal vulnerability was identified in GitHub Enterprise Server management console that allowed the bypass of CSRF protections. This could potentially lead to privilege escalation. To exploit this vulnerability, an attacker would need to target a user that was actively logged into the management console. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.5 and was fixed in versions 3.1.19, 3.2.11, 3.3.6, 3.4.1.
CVE-2022-23732

EPSS

0.002

Percentile

56.0%

Related for H1:1497169