An insufficient entropy vulnerability was identified in GitHub Enterprise Server (GHES) that allowed an attacker to brute force a user invitation to the GHES Management Console. To exploit this vulnerability, an attacker would need knowledge that a user invitation was pending. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1. This vulnerability was reported via the GitHub Bug Bounty program.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_P

Published: 2023-12-21T20:45:45.845Z

Updated: 2023-12-21T20:45:45.845Z

Reserved: 2023-10-24T13:41:13.390Z


Link: CVE-2023-46648

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-12-21T21:15:09.257

Modified: 2023-12-29T15:40:50.423


Link: CVE-2023-46648

JSON object: View

cve-icon Redhat Information

No data.

CWE