A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when configuring GeoJSON settings. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.13 and was fixed in versions 3.8.17, 3.9.12, 3.10.9, 3.11.7, and 3.12.1. This vulnerability was reported via the GitHub Bug Bounty program.
An attacker with editor role in the Management Console can inject malicious system commands while configuring GeoJSON settings. Lack of proper input validation (CWE-20) causes injected commands to be executed with system privileges, leading to obtaining administrative SSH access to the GitHub Enterprise Server instance. The attack is possible remotely without user interaction, but requires possession of an account with editor role in the Management Console.
An attacker can gain full administrative access (root SSH) to a GitHub Enterprise Server instance, enabling them to take control of the entire environment, including code repositories, user data, and system configuration.
GitHub Enterprise Server should be updated to version 3.8.17, 3.9.12, 3.10.9, 3.11.7, or 3.12.1 (accordingly for the used branch). Additionally, it is recommended to restrict access to the Management Console only to trusted users and to audit accounts with the editor role.
All GitHub Enterprise Server versions prior to 3.13, including branches 3.8, 3.9, 3.10, 3.11, and 3.12.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HGitHub Enterprise Server
APPGithub< 3.8.173.9.0 – 3.9.12 (excl.)3.10.0 – 3.10.9 (excl.)3.11.0 – 3.11.7 (excl.)3.12.0 – 3.12.1 (excl.)
Related vulnerabilities
SSRF z path traversal w GitHub Enterprise Server — dostęp do wewnętrznych usług
Obejście uwierzytelniania SAML SSO w GitHub Enterprise Server
XML Signature Wrapping w GitHub Enterprise Server — fałszowanie SAML
Authentication bypass w GitHub Enterprise Server via SAML SSO
Command injection w GitHub Enterprise Server — przejęcie dostępu SSH admina