CVE-2022-46258: Incorrect Authorization in GitHub Enterprise Server leads to Action Workflow modifications without Workflow Scope
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository-scoped token with read/write access to modify Action Workflow files without a Workflow scope. The Create or Update file contents API should enforce workflow scope. This vulnerability affected all versions of GitHub Enterprise Server prior to version 3.7 and was fixed in versions 3.3.16, 3.4.11, 3.5.8, and 3.6.4. This vulnerability was reported via the GitHub Bug Bounty program.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-46258?
CVE-2022-46258 is an incorrect authorization vulnerability in GitHub Enterprise Server.
What is the severity of CVE-2022-46258?
The severity of CVE-2022-46258 is medium with a CVSS score of 6.5.
How does CVE-2022-46258 affect GitHub Enterprise Server?
CVE-2022-46258 affects GitHub Enterprise Server versions up to 3.3.16, 3.4.0 to 3.4.11, 3.5.0 to 3.5.8, and 3.6.0 to 3.6.4.
How can I fix CVE-2022-46258?
To fix CVE-2022-46258, update GitHub Enterprise Server to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2022-46258?
More information about CVE-2022-46258 can be found in the GitHub Enterprise Server release notes.