TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2023-6804

MEDIUM
6.5

Beschreibung

Improper privilege management allowed arbitrary workflows to be committed and run using an improperly scoped PAT. To exploit this, a workflow must have already existed in the target repo. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.

CVE Details

CVSS v3.1 Bewertung6.5
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
AngriffsvektorLOCAL
KomplexitatHIGH
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht12/21/2023
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0

This product uses data from the NVD API but is not endorsed or certified by the NVD.