Medium severity4.8NVD Advisory· Published Aug 30, 2023· Updated Jun 17, 2026
CVE-2023-23765
CVE-2023-23765
Description
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request. To exploit this vulnerability, an attacker would need write access to the repository. This vulnerability was reported via the GitHub Bug Bounty Program https://bounty.github.com/ .
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*range: >=3.6.0,<3.6.16
- cpe:2.3:a:github:enterprise_server:3.9.0:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 3.6.0
Patches
Vulnerability mechanics
References
4- docs.github.com/en/[email protected]/admin/release-notesnvdRelease Notes
- docs.github.com/en/[email protected]/admin/release-notesnvdRelease Notes
- docs.github.com/en/[email protected]/admin/release-notesnvdRelease Notes
- docs.github.com/en/[email protected]/admin/release-notesnvdRelease Notes
News mentions
0No linked articles in our index yet.