← All CVEs

CVE-2024-0200

high · 7.2

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead to the execution of user-controlled methods and remote code execution. To exploit this bug, an actor would need to be logged into an account on the GHES instance with the organization owner role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.8.13, 3.9.8, 3.10.5, and 3.11.3. This vulnerability was reported via the GitHub Bug Bounty program.

7.2
CVSS
71.7%
EPSS (exploit prob.)
99th
EPSS percentile
2024-01-16
Published

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L

Weaknesses

CWE-470

Affected products

VendorProductAffected versions
githubenterprise_server>= 3.8.0, < 3.8.13
githubenterprise_server>= 3.9.0, < 3.9.8
githubenterprise_server>= 3.10.0, < 3.10.5
githubenterprise_server>= 3.11.0, < 3.11.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-0200