ZeroHour

CVE-2023-6690

CVSS 3.1
2.0 low
EPSS
<1%p25
Published
()
Modified
Description

A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphQL mutation to alter repository permissions during the transfer. This vulnerability affected GitHub Enterprise Server version 3.8.0 and above and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.

Vendors
github
Products
enterprise server
Weakness
CWE-367
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.