Impact
A missing authorization flaw in GitHub Enterprise Server’s GraphQL API enables any repository collaborator with write access to delete the repository’s current default branch. By doing so, the attacker can promote a branch of their choosing to become the new default, effectively bypassing pull‑request review requirements if branch deletion is not restricted. The consequence is that subsequent clones and default‑branch API requests will retrieve the attacker‑controlled content, compromising the integrity of the repository code base and potentially facilitating further attacks.
Affected Systems
The vulnerability affects GitHub Enterprise Server releases in the 3.18, 3.19, 3.20, 3.21, and 3.22 series. Patches are available in 3.18.16, 3.19.13, 3.20.9, 3.21.7, and 3.22.2, and all earlier patch releases in those major series remain vulnerable.
Risk and Exploitability
The CVSS score of 6 indicates a moderate severity, while the EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. An attacker who already has repository write access can exploit this via the GraphQL API, which implies the attack vector is internal or via authenticated access to the API.
OpenCVE Enrichment