CVE-2023-23764: Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff within the GitHub pull request UI. To do so, an attacker would need write access to the repository. This vulnerability affected GitHub Enterprise Server versions 3.7.0 and above and was fixed in versions 3.7.9, 3.8.2, and 3.9.1. This vulnerability was reported via the GitHub Bug Bounty program.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-23764?
CVE-2023-23764 is an incorrect comparison vulnerability in GitHub Enterprise Server that allows commit smuggling by displaying an incorrect diff within the GitHub pull request UI.
How does CVE-2023-23764 affect GitHub Enterprise Server?
CVE-2023-23764 affects GitHub Enterprise Server version 3.9.0 and earlier.
What is the severity of CVE-2023-23764?
CVE-2023-23764 has a severity rating of 7.1 (high).
How can an attacker exploit CVE-2023-23764?
To exploit CVE-2023-23764, an attacker would need write access to the repository on GitHub Enterprise Server.
Are there any fixes or patches available for CVE-2023-23764?
Yes, fixes are available for CVE-2023-23764. It is recommended to update GitHub Enterprise Server to version 3.9.1 or apply the necessary patches mentioned in the release notes for versions 3.7.9 and 3.8.2.