CVE-2023-6802: Sensitive Information in Log File in GitHub Enterprise Server
An insertion of sensitive information into the log file in the audit log in GitHub Enterprise Server was identified that could allow an attacker to gain access to the management console. To exploit this, an attacker would need access to the log files for the GitHub Enterprise Server appliance, a backup archive created with GitHub Enterprise Server Backup Utilities, or a service which received streamed logs. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6802?
CVE-2023-6802 has a high severity rating due to the potential exposure of sensitive information in the audit log.
How do I fix CVE-2023-6802?
To fix CVE-2023-6802, upgrade GitHub Enterprise Server to version 3.8.12, 3.9.7, 3.10.4, or 3.11.0.
What versions of GitHub Enterprise Server are affected by CVE-2023-6802?
CVE-2023-6802 affects GitHub Enterprise Server versions 3.8.0 to 3.8.12, 3.9.0 to 3.9.7, and 3.10.0 to 3.10.4.
What could an attacker do if CVE-2023-6802 is exploited?
If CVE-2023-6802 is exploited, an attacker could potentially gain unauthorized access to the management console.
Is CVE-2023-6802 a critical vulnerability?
Yes, CVE-2023-6802 is considered critical due to its potential to allow access to sensitive information.