CVE-2023-6690
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphQL mutation to alter repository permissions during the transfer. This vulnerability affected GitHub Enterprise Server version 3.8.0 and above and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.
Una condición de ejecución en GitHub Enterprise Server permitió a un administrador existente mantener los permisos en los repositorios transferidos al realizar una mutación GraphQL para alterar los permisos del repositorio durante la transferencia. Esta vulnerabilidad afectó a GitHub Enterprise Server versión 3.8.0 y superiores y se solucionó en las versiones 3.8.12, 3.9.7, 3.10.4 y 3.11.1.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-12-11 CVE Reserved
- 2023-12-21 CVE Published
- 2024-08-02 CVE Updated
- 2024-11-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
CAPEC
- CAPEC-29: Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions
References (4)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Github Search vendor "Github" | Enterprise Server Search vendor "Github" for product "Enterprise Server" | >= 3.8.0 < 3.8.12 Search vendor "Github" for product "Enterprise Server" and version " >= 3.8.0 < 3.8.12" | - |
Affected
| ||||||
Github Search vendor "Github" | Enterprise Server Search vendor "Github" for product "Enterprise Server" | >= 3.9.0 < 3.9.7 Search vendor "Github" for product "Enterprise Server" and version " >= 3.9.0 < 3.9.7" | - |
Affected
| ||||||
Github Search vendor "Github" | Enterprise Server Search vendor "Github" for product "Enterprise Server" | >= 3.10.0 < 3.10.4 Search vendor "Github" for product "Enterprise Server" and version " >= 3.10.0 < 3.10.4" | - |
Affected
| ||||||
Github Search vendor "Github" | Enterprise Server Search vendor "Github" for product "Enterprise Server" | 3.11.0 Search vendor "Github" for product "Enterprise Server" and version "3.11.0" | - |
Affected
|