← Back to browse · API

CVE-2024-0507

Severity
MEDIUM
CVSS
6.5
EPSS
0.658
Risk score
49.03
CISA KEV
No
PoC
No
Published
2024-01-16
Modified
2024-10-22
First seen
2026-08-07
Aliases
EUVD-2024-16302, GHSA-WMC3-GVP9-38QP
Products
GitHub:Enterprise Server, GitHub:Enterprise Server 3.10.0 ≤3.10.4, GitHub:Enterprise Server 3.11.0 ≤3.11.2, GitHub:Enterprise Server 3.8.0 ≤3.8.12, GitHub:Enterprise Server 3.9.0 ≤3.9.7
Sources
euvd EUVD-2024-16302

Description

An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.11.3, 3.10.5, 3.9.8, and 3.8.13 This vulnerability was reported via the GitHub Bug Bounty program.

References