Impact
A time‑of‑check time‑of‑use race condition in GitHub Enterprise Server allows an attacker to execute arbitrary code on the server. The flaw requires the attacker to be an authenticated user with write access to a repository and to precisely time concurrent upload requests. If exploited, the attacker can gain full control of the affected system, compromising confidentiality, integrity, and availability of all repositories and services running on the instance.
Affected Systems
GitHub Enterprise Server versions earlier than 3.22 are affected. The vulnerability was resolved in releases 3.17.20, 3.18.14, 3.19.11, 3.20.7, 3.21.5, and 3.22.0.
Risk and Exploitability
The vulnerability scores a CVSS of 7.7, indicating a high likelihood of serious impact. The EPSS score is not available, so the current probability of exploitation is unknown, but the issue is not listed in CISA KEV catalogs. Based on the description, the attack vector is inferred to be an authenticated internal attacker who can write to a repository, requiring precise timing of file‑upload operations. No known public exploits are documented, but the high severity and required preconditions suggest an internal threat model should be considered.
OpenCVE Enrichment