CVE-2023-51379: Incorrect Authorization for Issue Comments in GitHub Enterprise Server
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be updated with an improperly scoped token. This vulnerability did not allow unauthorized access to any repository content as it also required contents:write and issues:read permissions. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.17.19, 3.8.12, 3.9.7, 3.10.4, and 3.11.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51379?
The severity of CVE-2023-51379 is classified as medium due to the potential for unauthorized updates to issue comments.
How do I fix CVE-2023-51379?
To fix CVE-2023-51379, update your GitHub Enterprise Server to a version that provides the necessary security patch, such as 3.7.19 or higher.
Which versions of GitHub Enterprise Server are affected by CVE-2023-51379?
CVE-2023-51379 affects GitHub Enterprise Server versions 3.7.0 to 3.7.19, 3.8.0 to 3.8.12, 3.9.0 to 3.9.7, 3.10.0 to 3.10.4, and 3.11.0.
What type of vulnerability is CVE-2023-51379?
CVE-2023-51379 is categorized as an incorrect authorization vulnerability.
Does CVE-2023-51379 allow unauthorized access to repository content?
No, CVE-2023-51379 does not allow unauthorized access to repository content, but it can permit unauthorized updates to issue comments.