Skip to main content

Vendor/product archive

github / enterprise_server CVEs

Beta · best-effort

116 CVEs tagged to github / enterprise_server14 Critical, 43 High, 57 Medium, 2 Low, 0 Unrated.

CVE-2024-5566

Published Jul 16, 2024

An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes defined on the related Personal Access Token. This v…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5746

Published Jun 20, 2024

A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the Site Administrator role to gain arbitrary code execution c…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4985

Published May 20, 2024

An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional encrypted assertions…

CVSS 10.0 · Critical
evidence mentions
7
Buzz score
28.8
Vendor/product tagsBeta · best-effort

CVE-2024-2440

Published Apr 19, 2024

A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on a detached repository by making a GraphQL mutation to alter repository permission…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3684

Published Apr 19, 2024

A server side request forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin access…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3646

Published Apr 19, 2024

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3470

Published Apr 19, 2024

An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use a deploy key pertaining to an organization to bypass an o…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1908

Published Mar 21, 2024

An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use the Enterprise Actions GitHub Connect download token to f…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2748

Published Mar 21, 2024

A Cross Site Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker to execute unauthorized actions on behalf of an unsuspecting user. A…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2469

Published Mar 20, 2024

An attacker with an Administrator role in GitHub Enterprise Server could gain SSH root access via remote code execution. This vulnerability affected GitHub Enterprise Server versi…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2443

Published Mar 20, 2024

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-1482

Published Feb 14, 2024

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to create new branches in public repositories and run arbitrary GitHub…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1378

Published Feb 13, 2024

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-1374

Published Feb 13, 2024

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-1372

Published Feb 13, 2024

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-1369

Published Feb 13, 2024

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-1359

Published Feb 13, 2024

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-1355

Published Feb 13, 2024

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-1354

Published Feb 13, 2024

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1084

Published Feb 13, 2024

Cross-site Scripting in the tag name pattern field in the tag protections UI in GitHub Enterprise Server allows a malicious website that requires user interaction and social engin…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1082

Published Feb 13, 2024

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker to gain unauthorized read permission to files by deploying arbitrary symbolic li…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0507

Published Jan 16, 2024

An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. Th…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0200

Published Jan 16, 2024

An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead to the execution of user-contr…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-6847

Published Dec 21, 2023

An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed a bypass of Private Mode by using a specially crafted API request. To exploit this…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6804

Published Dec 21, 2023

Improper privilege management allowed arbitrary workflows to be committed and run using an improperly scoped PAT. To exploit this, a workflow must have already existed in the targ…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-75 of 116 CVEsPage 3 of 5