Skip to main content

Vendor/product archive

github / enterprise_server CVEs

Beta · best-effort

116 CVEs tagged to github / enterprise_server14 Critical, 43 High, 57 Medium, 2 Low, 0 Unrated.

CVE-2025-11578

Published Nov 10, 2025

A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH access to the appliance by exploiti…

CVSS 7.5 · High
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2025-8447

Published Aug 26, 2025

An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any repository to retrieve limited code content from another…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-6981

Published Jul 15, 2025

An incorrect authorization vulnerability allowed unauthorized read access to the contents of internal repositories for contractor accounts when the Contractors API feature was ena…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-6600

Published Jul 1, 2025

An exposure of sensitive information vulnerability was identified in GitHub Enterprise Server that could allow an attacker to disclose the names of private repositories within an…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3509

Published Apr 17, 2025

A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute arbitrary code by exploiting the pre-receive hook function…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-3246

Published Apr 17, 2025

An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting in GitHub Markdown that used `$$..$$` math blocks.…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-3124

Published Apr 17, 2025

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise have acc…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10001

Published Jan 29, 2025

A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious code into the query selector via the identity property in the…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-23369

Published Jan 21, 2025

An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed signature spoofing for unauthorized internal users. Inst…

CVSS 7.6 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2024-8810

Published Nov 7, 2024

A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from an organization administrator. An attacker would require an…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10824

Published Nov 7, 2024

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauthorized internal users to access sensitive secret scanning alert data intended o…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10007

Published Nov 7, 2024

A path collision and arbitrary code execution vulnerability was identified in GitHub Enterprise Server that allowed container escape to escalate to root via ghe-firejail path. Exp…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9539

Published Oct 11, 2024

An information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allowing the attacker to retrieve metadata information of a user…

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-9487

Published Oct 10, 2024

An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unaut…

CVSS 9.5 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-8770

Published Sep 23, 2024

A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user informatio…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8263

Published Sep 23, 2024

An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affect…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7711

Published Aug 20, 2024

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, and labels of any issue inside a public r…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-6800

Published Aug 20, 2024

An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed s…

CVSS 9.5 · Critical
evidence mentions
5
Buzz score
27.4
Vendor/product tagsBeta · best-effort

CVE-2024-6337

Published Aug 20, 2024

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only content: read and pull_request_write: write permissions to…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-6395

Published Jul 16, 2024

An exposure of sensitive information vulnerability in GitHub Enterprise Server would allow an attacker to enumerate the names of private repositories that utilize deploy keys. Thi…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6336

Published Jul 16, 2024

A Security Misconfiguration vulnerability in GitHub Enterprise Server allowed sensitive information disclosure to unauthorized users in GitHub Enterprise Server by exploiting orga…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5817

Published Jul 16, 2024

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed read access to issue content via GitHub Projects. This was only exploitable in int…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5816

Published Jul 16, 2024

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App to retain access to the repository via a scoped user access…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5815

Published Jul 16, 2024

A Cross-Site Request Forgery vulnerability in GitHub Enterprise Server allowed write operations on a victim-owned repository by exploiting incorrect request types. A mitigating fa…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5795

Published Jul 16, 2024

A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause unbounded resource exhaustion by sending a large payload to the Git…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort
Showing 26-50 of 116 CVEsPage 2 of 5