CVE-2023-6690: GitHub Enterprise Server
Low severity, CVSS 2.0. EPSS: 0.3% chance of exploitation in the next 30 days.
A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphQL mutation to alter repository permissions during the transfer. This vulnerability affected GitHub Enterprise Server version 3.8.0 and above and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.
Affected products
- GitHub Enterprise Server: from 3.8.0, before 3.8.12 (fixed in 3.8.12); from 3.9.0, before 3.9.7 (fixed in 3.9.7); from 3.10.0, before 3.10.4 (fixed in 3.10.4); version 3.11.0 only
Published 2023-12-21. Last modified 2026-06-17.