CVE-2024-0200 is an unsafe reflection vulnerability in GitHub Enterprise Server (GHES) that could lead to reflection injection and remote code execution. This critical flaw affects all GHES versions prior to 3.12, requiring an organization owner account for exploitation. With a CVSS score of 9.8 (CRITICAL), the vulnerability has a high potential impact, allowing for complete compromise of confidentiality, integrity, and availability. While not currently in the KEV catalog, a Nuclei template for authenticated RCE exists, and the vulnerability has garnered significant community discussion and media coverage, including a detailed analysis.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.10.0, < 3.10.5CPE match | cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* | ||
>= 3.11.0, < 3.11.3CPE match | cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* | ||
>= 3.8.0, < 3.8.13CPE match | cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* | ||
>= 3.9.0, < 3.9.8CPE match | cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.