VYPR
Medium severity4.8NVD Advisory· Published Aug 30, 2023· Updated Jun 17, 2026

CVE-2023-23765

CVE-2023-23765

Description

An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request. To exploit this vulnerability, an attacker would need write access to the repository. This vulnerability was reported via the GitHub Bug Bounty Program https://bounty.github.com/ .

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*range: >=3.6.0,<3.6.16
    • cpe:2.3:a:github:enterprise_server:3.9.0:*:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 3.6.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.