Skip to main content

Vendor/product archive

github / enterprise_server CVEs

Beta · best-effort

116 CVEs tagged to github / enterprise_server14 Critical, 43 High, 57 Medium, 2 Low, 0 Unrated.

CVE-2022-46255

Published Dec 14, 2022

An improper limitation of a pathname to a restricted directory vulnerability was identified in GitHub Enterprise Server that enabled remote code execution. A check was added withi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-23737

Published Dec 1, 2022

An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privileges to create or delete pages via the API. To exp…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23740

Published Nov 23, 2022

CRITICAL: An improper neutralization of argument delimiters in a command vulnerability was identified in GitHub Enterprise Server that enabled remote code execution. To exploit th…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23738

Published Nov 1, 2022

An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to access private repository files through a public repository. T…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23734

Published Oct 19, 2022

A deserialization of untrusted data vulnerability was identified in GitHub Enterprise Server that could potentially lead to remote code execution on the SVNBridge. To exploit this…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23733

Published Aug 2, 2022

A stored XSS vulnerability was identified in GitHub Enterprise Server that allowed the injection of arbitrary attributes. This injection was blocked by Github's Content Security P…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23732

Published Apr 5, 2022

A path traversal vulnerability was identified in GitHub Enterprise Server management console that allowed the bypass of CSRF protections. This could potentially lead to privilege…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41599

Published Feb 18, 2022

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. To exploit this vulnerability, an attac…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41598

Published Jan 25, 2022

A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's user-authorization web flow than…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22870

Published Nov 10, 2021

A path traversal vulnerability was identified in GitHub Pages builds on GitHub Enterprise Server that could allow an attacker to read system files. To exploit this vulnerability,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22869

Published Sep 24, 2021

An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to. This affects…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-22868

Published Sep 24, 2021

A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22867

Published Jul 14, 2021

A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22866

Published May 14, 2021

A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's user-authorization web flow than…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22865

Published Apr 2, 2021

An improper access control vulnerability was identified in GitHub Enterprise Server that allowed access tokens generated from a GitHub App's web authentication flow to read privat…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22864

Published Mar 23, 2021

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options u…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 101-116 of 116 CVEsPage 5 of 5