Back

MEDIUM

Incorrect Authorization in GitHub Enterprise Server leads to Action Workflow modifications without Workflow Scope

Published Jan 9, 2023

Description

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository-scoped token with read/write access to modify Action Workflow files without a Workflow scope. The Create or Update file contents API should enforce workflow scope. This vulnerability affected all versions of GitHub Enterprise Server prior to version 3.7 and was fixed in versions 3.3.16, 3.4.11, 3.5.8, and 3.6.4. This vulnerability was reported via the GitHub Bug Bounty program.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_P
Published Jan 9, 2023
Updated Apr 9, 2025
Reserved Nov 28, 2022

CISA Vulnrichment

Updated Apr 9, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_P
Published Jan 9, 2023
Updated Apr 9, 2025

GitHub

No data