← Back to browse · API

CVE-2024-0200

Severity
HIGH
CVSS
7.2
EPSS
0.71725
Risk score
53.9
CISA KEV
No
PoC
No
Published
2024-01-16
Modified
2024-08-01
First seen
2026-08-08
Aliases
EUVD-2024-15999, GHSA-G39R-HH73-78XJ
Products
GitHub:Enterprise Server, GitHub:Enterprise Server 3.10.0 <3.10.5, GitHub:Enterprise Server 3.11.0 <3.11.3, GitHub:Enterprise Server 3.8.0 <3.8.13, GitHub:Enterprise Server 3.9.0 <3.9.8
Sources
euvd EUVD-2024-15999

Description

An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead to the execution of user-controlled methods and remote code execution. To exploit this bug, an actor would need to be logged into an account on the GHES instance with the organization owner role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.8.13, 3.9.8, 3.10.5, and 3.11.3. This vulnerability was reported via the GitHub Bug Bounty program.

References