CVE-2022-23741: GitHub Enterprise Server
High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a scoped user-to-server token to escalate to full admin/owner privileges. An attacker would require an account with admin access to install a malicious GitHub App. This vulnerability was fixed in versions 3.3.17, 3.4.12, 3.5.9, and 3.6.5. This vulnerability was reported via the GitHub Bug Bounty program.
Affected products
- GitHub Enterprise Server: before 3.3.17 (fixed in 3.3.17); from 3.4.0, before 3.4.12 (fixed in 3.4.12); from 3.5.0, before 3.5.9 (fixed in 3.5.9); from 3.6.0, before 3.6.5 (fixed in 3.6.5)
Published 2022-12-14. Last modified 2026-06-17.