Impact
A time‑of‑check time‑of‑use race condition flaw in GitHub Enterprise Server allows an authenticated user with write access to a repository to launch concurrently timed upload operations that can trigger arbitrary code execution on the server. The flaw exploits a race condition (CWE‑367) and grants an attacker full control of the instance, thereby compromising confidentiality, integrity, and availability of all repositories and associated services.
Affected Systems
GitHub Enterprise Server versions earlier than 3.22 are affected. The vulnerability was resolved in releases 3.17.20, 3.18.14, 3.19.11, 3.20.7, and 3.21.5.
Risk and Exploitability
The vulnerability scores a CVSS of 7.7, indicating a high likelihood of serious impact. The EPSS score is < 1%, indicating a low probability of exploitation, and it’s not listed in CISA KEV catalogs. Based on the description, the attack vector is inferred to be an authenticated internal attacker with write access to a repository who can precisely time concurrent upload requests. No known public exploits are documented, but the high severity and required preconditions suggest an internal threat model should be considered.
OpenCVE Enrichment