CVE-2022-23740 is a critical remote code execution vulnerability affecting GitHub Enterprise Server version 3.7.0. It stems from improper neutralization of argument delimiters in a command, allowing an attacker with permissions to create and build GitHub Pages via GitHub Actions to execute arbitrary code. The vulnerability carries a CVSS score of 8.8 (High), indicating a severe impact with high confidentiality, integrity, and availability compromise. Exploitation requires low privileges and no user interaction, making it relatively easy to leverage once access is gained. There is currently no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, which is typical for the vast majority of vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.7.0CPE matchmatch criteria | cpe:2.3:a:github:enterprise_server:3.7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.