MEDIUM
Race Condition allows Unauthorized Outside Collaborator
Published Dec 21, 2023
5.8
MEDIUMCVSS 3.1
EPSS 0.17%
Description
A race condition in GitHub Enterprise Server allows an outside collaborator to be added while a repository is being transferred. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.
Affected products
-
- Version 3.10StatusaffectedConstraints<=3.10.3
- Version 3.11StatusaffectedConstraints<=3.11.0
- Version 3.8StatusaffectedConstraints<=3.8.11
- Version 3.9StatusaffectedConstraints<=3.9.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| GitHub | Enterprise Server | affected |
|
OR
- ≥ 3.8.0 · < 3.8.12
- ≥ 3.9.0 · < 3.9.7
- ≥ 3.10.0 · < 3.10.4
- 3.11.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.4 Release Notes
- https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.1 Release Notes
- https://docs.github.com/en/enterprise-server@3.8/admin/release-notes#3.8.12 Release Notes
- https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.7 Release Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59014 Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_P
Published Dec 21, 2023
Updated Aug 2, 2024
Reserved Dec 13, 2023
Link CVE-2023-6803
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2023-59014 Assigner GitHub_P
Published Dec 21, 2023
Updated Aug 2, 2024
Exploited since n/a
Link EUVD-2023-59014