Improper privilege management... CVE-2023-6804

- AV AC AU C I A
发布: 2023-12-21
修订: 2023-12-29

Improper privilege management allowed arbitrary workflows to be committed and run using an improperly scoped PAT. To exploit this, a workflow must have already existed in the target repo. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.

0%
暂无可用Exp或PoC
当前有4条受影响产品信息