CVE-2024-2469
CVE-2024-2469: Remote Code Execution in GitHub Enterprise Server. An administrator can gain SSH root access via remote code execution. This vulnerability affects GitHub Enterprise Server versions 3.8.0 and later, patched in versions 3.8.17, 3.9.12, 3.10.9, 3.11.7 and 3.12.1. Although the CVSS score is 8, the SOCRadar Vulnerability Risk Score (SVRS) is 30, indicating a lower immediate risk profile compared to other vulnerabilities, but continuous monitoring is still advised, especially with the CWE-20 tag. Successful exploitation would grant complete control of the GitHub Enterprise Server instance. Mitigate this risk by updating to a patched version of GitHub Enterprise Server. The vulnerability was identified through the GitHub Bug Bounty program.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.