CVE-2023-6803

Published Dec 21, 2023

Last updated a year ago

Overview

Description
A race condition in GitHub Enterprise Server allows an outside collaborator to be added while a repository is being transferred. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.
Source
product-cna@github.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
4
Impact score
3.6
Exploitability score
0.3
Vector string
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N
Severity
MEDIUM

Weaknesses

nvd@nist.gov
CWE-367
product-cna@github.com
CWE-367

Social media

Hype score
Not currently trending

Configurations