CVE-2023-46649: Race Condition allows Administrative Access on Organization Repositories
A race condition in GitHub Enterprise Server was identified that could allow an attacker administrator access. To exploit this, an organization needs to be converted from a user. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.7.19, 3.8.12, 3.9.7, 3.10.4, and 3.11.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-46649?
CVE-2023-46649 is classified with a high severity due to the potential for an attacker to gain administrator access.
How do I fix CVE-2023-46649?
To fix CVE-2023-46649, you must upgrade GitHub Enterprise Server to version 3.7.19 or later, 3.8.12 or later, 3.9.7 or later, 3.10.4 or later, or 3.11.0.
Which versions of GitHub Enterprise Server are affected by CVE-2023-46649?
CVE-2023-46649 affects all versions of GitHub Enterprise Server from 3.7.0 up to but not including version 3.7.19, and various versions up to their respective fixes.
Can CVE-2023-46649 be exploited without user conversion?
Exploitation of CVE-2023-46649 requires the organization to be converted from a user to allow the race condition to be triggered.
What is the nature of CVE-2023-46649?
CVE-2023-46649 is a race condition vulnerability that can lead to unauthorized administrator access in GitHub Enterprise Server.