CVE-2022-23733: Stored XSS vulnerability in GitHub Enterprise Server leading to injection of arbitrary attributes
A stored XSS vulnerability was identified in GitHub Enterprise Server that allowed the injection of arbitrary attributes. This injection was blocked by Github's Content Security Policy (CSP). This vulnerability affected all versions of GitHub Enterprise Server prior to 3.6 and was fixed in versions 3.3.11, 3.4.6 and 3.5.3. This vulnerability was reported via the GitHub Bug Bounty program.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-23733?
CVE-2022-23733 is a stored XSS vulnerability identified in GitHub Enterprise Server that allowed the injection of arbitrary attributes.
How does this vulnerability impact GitHub Enterprise Server?
This vulnerability allows an attacker to inject arbitrary attributes, potentially leading to cross-site scripting (XSS) attacks.
Which versions of GitHub Enterprise Server are affected by CVE-2022-23733?
All versions of GitHub Enterprise Server prior to 3.6 are affected by this vulnerability.
How can I fix the CVE-2022-23733 vulnerability?
To fix the CVE-2022-23733 vulnerability, it is recommended to update GitHub Enterprise Server to version 3.6 or later.
Where can I find more information about CVE-2022-23733?
You can find more information about CVE-2022-23733 in the official GitHub Enterprise Server release notes: [Link 1](https://docs.github.com/en/enterprise-server@3.3/admin/release-notes#3.3.11), [Link 2](https://docs.github.com/en/enterprise-server@3.4/admin/release-notes#3.4.6), [Link 3](https://docs.github.com/en/enterprise-server@3.5/admin/release-notes#3.5.3).