Vulnerability record · CVE-2017-18365 · published 28 March 2019
CVE-2017-18365: Github deserialization of untrusted data vulnerability
Github · Github
The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to execute arbitrary code. This occurs because the enterprise session secret is always the same, and can be found in the product's source code. By sending a crafted cookie signed with this secret, one can call Marshal.load with arbitrary data, which is a problem because the Marshal data format allows Ruby objects.
Description
The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to execute arbitrary code. This occurs because the enterprise session secret is always the same, and can be found in the product's source code. By sending a crafted cookie signed with this secret, one can call Marshal.load with arbitrary data, which is a problem because the Marshal data format allows Ruby objects.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://enterprise.github.com/releases/2.8.7/notes | Vendor Advisory |
| https://www.exablue.de/blog/2017-03-15-github-enterprise-remote-code-execution.html | ExploitThird Party Advisory |
| https://enterprise.github.com/releases/2.8.7/notes | Vendor Advisory |
| https://www.exablue.de/blog/2017-03-15-github-enterprise-remote-code-execution.html | ExploitThird Party Advisory |
Track CVE-2017-18365 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-18365), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.