Skip to main content

Vendor/product archive

github / enterprise_server CVEs

Beta · best-effort

116 CVEs tagged to github / enterprise_server14 Critical, 43 High, 57 Medium, 2 Low, 0 Unrated.

CVE-2023-6803

Published Dec 21, 2023

A race condition in GitHub Enterprise Server allows an outside collaborator to be added while a repository is being transferred. This vulnerability affected all versions of GitHub…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6802

Published Dec 21, 2023

An insertion of sensitive information into the log file in the audit log in GitHub Enterprise Server was identified that could allow an attacker to gain access to the management c…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6746

Published Dec 21, 2023

An insertion of sensitive information into log file vulnerability was identified in the log files for a GitHub Enterprise Server back-end service that could permit an `adversary i…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6690

Published Dec 21, 2023

A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphQL mutation to alter repository permiss…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-51380

Published Dec 21, 2023

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be read with an improperly scoped token. This vulnerability affe…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-51379

Published Dec 21, 2023

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be updated with an improperly scoped token. This vulnerability d…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46649

Published Dec 21, 2023

A race condition in GitHub Enterprise Server was identified that could allow an attacker administrator access. To exploit this, an organization needs to be converted from a user.…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46648

Published Dec 21, 2023

An insufficient entropy vulnerability was identified in GitHub Enterprise Server (GHES) that allowed an attacker to brute force a user invitation to the GHES Management Console. T…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-46647

Published Dec 21, 2023

Improper privilege management in all versions of GitHub Enterprise Server allows users with authorized access to the management console with an editor role to escalate their privi…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-46646

Published Dec 21, 2023

Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get a check run" API endpoint. This vulnera…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46645

Published Dec 21, 2023

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when building a GitHub Pages site. To exploit this vulnerability, an…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23766

Published Sep 22, 2023

An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request. To do s…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23763

Published Sep 1, 2023

An authorization/sensitive information disclosure vulnerability was identified in GitHub Enterprise Server that allowed a fork to retain read access to an upstream repository afte…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23765

Published Aug 30, 2023

An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request. To expl…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23764

Published Jul 27, 2023

An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff within the GitHub pull request UI. T…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23762

Published Apr 7, 2023

An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff. To do so, an attacker would need wr…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23761

Published Apr 7, 2023

An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to modify other users' secret gists by authenticating throug…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23760

Published Mar 8, 2023

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site. To exploit this vulnerability, an a…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46257

Published Mar 7, 2023

An information disclosure vulnerability was identified in GitHub Enterprise Server that allowed private repositories to be added to a GitHub Actions runner group via the API by a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22381

Published Mar 2, 2023

A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment variables from a single environment variable value in GitHub A…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22380

Published Feb 16, 2023

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when building a GitHub Pages site. To exploit this vulnerability, an…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23739

Published Jan 17, 2023

An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileges in GraphQL API requests from GitHub Apps. This vulnerabi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-46258

Published Jan 9, 2023

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository-scoped token with read/write access to modify Action Workflow files w…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23741

Published Dec 14, 2022

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a scoped user-to-server token to escalate to full admin/owner privileges. An attac…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-46256

Published Dec 14, 2022

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site. To exploit this vulnerability, an a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 76-100 of 116 CVEsPage 4 of 5