CVE-2023-23765
Dashboard / Vulnerabilities / CVE-2023-23765
CVE-2023-23765
Published: 30 Aug 2023Last Modified: 11 Mar 2026
Summary:
Details: An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request. To exploit this vulnerability, an attacker would need write access to the repository. This vulnerability was reported via the GitHub Bug Bounty Program https://bounty.github.com/ .
References: , https://docs.github.com/en/[email protected]/admin/release-notes#3.6.16, https://docs.github.com/en/[email protected]/admin/release-notes#3.7.13, https://docs.github.com/en/[email protected]/admin/release-notes#3.8.9, https://docs.github.com/en/[email protected]/admin/release-notes#3.9.1
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
