Impact
A Server‑Side Request Forgery flaw in GitHub Enterprise Server enabled an attacker to execute code on the instance when malicious pre‑receive hook code could impersonate an internal service. The vulnerability permitted the redirection of trusted internal requests to a privileged service, enabling any attacker with suitable privileges to run code with elevated rights. This grants complete control over the affected GitHub instance and potentially the underlying host.
Affected Systems
GitHub Enterprise Server versions prior to 3.22 are impacted. The vendor released mitigations in releases 3.17.20, 3.18.14, 3.19.11, 3.20.7, and 3.21.5. Any instance running an earlier release is vulnerable.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity. The EPSS score is currently unavailable, but the vulnerability is not listed in the CISA KEV catalog. Exploitation requires pre‑receive hook networking to be enabled and either site‑administrator rights or write access to a repository containing a configured pre‑receive hook. Attackers could thus gain remote code execution by simply committing malicious code to a permissible repository.
OpenCVE Enrichment