CVE-2023-23760: Path traversal in GitHub Enterprise Server leading to remote code execution
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to versions 3.8 and was fixed in versions 3.7.7, 3.6.10, 3.5.14, and 3.4.17. This vulnerability was reported via the GitHub Bug Bounty program.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this path traversal vulnerability?
The vulnerability ID is CVE-2023-23760.
What is the severity rating of CVE-2023-23760?
CVE-2023-23760 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2023-23760?
CVE-2023-23760 affects GitHub Enterprise Server versions up to 3.4.17, versions 3.5.0 to 3.5.14, versions 3.6.0 to 3.6.10, and versions 3.7.0 to 3.7.7.
How can an attacker exploit CVE-2023-23760?
To exploit CVE-2023-23760, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance.
Are there any references for CVE-2023-23760?
Yes, you can find references for CVE-2023-23760 at the following URLs: [https://docs.github.com/en/enterprise-server@3.4/admin/release-notes#3.4.17](https://docs.github.com/en/enterprise-server@3.4/admin/release-notes#3.4.17), [https://docs.github.com/en/enterprise-server@3.5/admin/release-notes#3.5.14](https://docs.github.com/en/enterprise-server@3.5/admin/release-notes#3.5.14), [https://docs.github.com/en/enterprise-server@3.6/admin/release-notes#3.6.10](https://docs.github.com/en/enterprise-server@3.6/admin/release-notes#3.6.10).