← Vulnerability feed

Vulnerability record · CVE-2021-22863 · published 3 March 2021

CVE-2021-22863: Github improper authorization vulnerability

Github · Github

An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allowed authenticated users of the instance to modify the maintainer collaboration permission of a pull request without proper authorization. By exploiting this vulnerability, an attacker would be able to gain access to head branches of pull requests opened on repositories of which they are a maintainer. Forking is disabled by default for organization owned private repositories and would prevent this vulnerability. Additionally, branch protections such as required pull request reviews or status checks would prevent unauthorized commits from being merged without further review or validation. This vulnerability affected all versions of GitHub Enterprise Server since 2.12.22 and was fixed in versions 2.20.24, 2.21.15, 2.22.7 and 3.0.1. This vulnerability was reported via the GitHub Bug Bounty program.

8.1 CVSS 3.1 High EPSS 1.0% · top 38.5% CWE-285 · Improper authorization
8.1CVSS 3.1 base score, v2 5.5
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allowed authenticated users of the instance to modify the maintainer collaboration permission of a pull request without proper authorization. By exploiting this vulnerability, an attacker would be able to gain access to head branches of pull requests opened on repositories of which they are a maintainer. Forking is disabled by default for organization owned private repositories and would prevent this vulnerability. Additionally, branch protections such as required pull request reviews or status checks would prevent unauthorized commits from being merged without further review or validation. This vulnerability affected all versions of GitHub Enterprise Server since 2.12.22 and was fixed in versions 2.20.24, 2.21.15, 2.22.7 and 3.0.1. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22863 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-10516Github improper authorization vulnerabilityAn improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissio…EPSS 1.6%9.8CVE-2017-18365Github deserialization of untrusted data vulnerabilityThe Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to execute ar…EPSS 21%8.8CVE-2020-10519Github command injection vulnerabilityA remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-cont…EPSS 3.1%8.8CVE-2020-10518Github command injection vulnerabilityA remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-cont…EPSS 3.7%7.5CVE-2012-2055Github improper control of dynamically-managed code vulnerabilityGitHub Enterprise before 20120304 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attack…EPSS 1.8%6.5CVE-2021-22861Github improper authorization vulnerabilityAn improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to gain write ac…EPSS 0.95%6.5CVE-2021-22862Github improper authorization vulnerabilityAn improper access control vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with the ability to fork a rep…EPSS 0.84%4.3CVE-2020-10517Github improper authorization vulnerabilityAn improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to determine the…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2021-22863), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.