CVE-2017-18365 affects GitHub Enterprise 2.8.x before 2.8.7. The Management Console uses a static, hardcoded enterprise session secret that is recoverable from the product source code. Because this secret is not unique per installation, an unauthenticated remote attacker can forge a valid Management Console session cookie for the /setup/unlock endpoint. The application then processes attacker-controlled serialized Ruby Marshal data and invokes Marshal.load on that data. Since Ruby Marshal deserialization can instantiate attacker-controlled objects, this results in insecure deserialization and enables arbitrary code execution in the context of the vulnerable GitHub Enterprise Management Console.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (modules/exploits/linux/http/github_enterprise_secret.rb) targeting Github Enterprise versions 2.8.0 through 2.8.6. The exploit leverages two vulnerabilities: a hardcoded session secret and unsafe Ruby object deserialization. By crafting a malicious session cookie (_gh_manage) signed with the known secret, the attacker can inject a serialized Ruby object that, when deserialized by the server, executes arbitrary code. The module includes logic to check for vulnerability, generate a serialized payload, and deliver it via a tampered session cookie to the main web interface (default HTTPS port 8443). The payload writes a base64-encoded executable to /tmp, decodes it, makes it executable, and runs it, providing remote code execution. The exploit is operational and requires the target to be running a vulnerable version of Github Enterprise with default configuration. The code is written in Ruby and is designed to be used within the Metasploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in GitHub Enterprise versions prior to 2.8.7 due to insecure deserialization in the Management Console's /setup/unlock endpoint, exploitable via a hardcoded session secret and Ruby Marshal.load.
A remote code execution vulnerability in GitHub Enterprise Management Console versions prior to 2.8.7, caused by insecure Ruby Marshal deserialization, allowing attackers to execute arbitrary code.
A remote code execution vulnerability in GitHub Enterprise 2.8.x before 2.8.7 due to a hardcoded session secret, which allows unauthenticated attackers to perform Ruby deserialization attacks.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.