Github Enterprise Server vulnerabilities
127 known vulnerabilities affecting github/enterprise_server.
Total CVEs
127
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL20HIGH39MEDIUM64LOW4
Vulnerabilities
Page 4 of 7
CVE-2023-23764P3HIGHCVSS 7.1≥ 3.7.0, < 3.7.9≥ 3.8.0, < 3.8.2+2 more2023-07-27
CVE-2023-23764 [HIGH] CWE-697 CVE-2023-23764: An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff within the GitHub pull request UI. To do so, an attacker would need write access to the repository. This vulnerability affected GitHub Enterprise Server versions 3.7.0 and above and was fixed in versions 3.7.9,
nvd
CVE-2024-1082P3MEDIUMCVSS 6.5fixed in 3.8.15≥ 3.9.0, < 3.9.10+3 more2024-02-13
CVE-2024-1082 [MEDIUM] CWE-22 CVE-2024-1082: A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker t
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker to gain unauthorized read permission to files by deploying arbitrary symbolic links to a GitHub Pages site with a specially crafted artifact tarball. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site
nvd
CVE-2024-5817P3MEDIUMCVSS 6.5≥ 3.9.0, < 3.9.17≥ 3.10.0, < 3.10.14+3 more2024-07-16
CVE-2024-5817 [MEDIUM] CWE-863 CVE-2024-5817: An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed rea
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed read access to issue content via GitHub Projects. This was only exploitable in internal repositories and required the attacker to have access to the corresponding project board. This vulnerability affected all versions of GitHub Enterprise Server prior to
nvd
CVE-2024-1482P3MEDIUMCVSS 6.5≥ 3.8.0, < 3.9.10≥ 3.10.0, < 3.10.7+4 more2024-02-14
CVE-2024-1482 [MEDIUM] CWE-863 CVE-2024-1482: An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to create new branches in public repositories and run arbitrary GitHub Actions workflows with permissions from the GITHUB_TOKEN. To exploit this vulnerability, an attacker would need access to the Enterprise Server. This vulnerability affected a
nvd
CVE-2024-10824P3MEDIUMCVSS 6.5≥ 3.13.0, < 3.13.2≥ 3.13.0, ≤ 3.13.12024-11-07
CVE-2024-10824 [MEDIUM] CWE-862 CVE-2024-10824: An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauth
An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauthorized internal users to access sensitive secret scanning alert data intended only for business owners. This issue could be exploited only by organization members with a personal access token (PAT) and required that secret scanning be enabled on user-
nvd
CVE-2023-23766P3MEDIUMCVSS 6.5fixed in 3.6.17≥ 3.7.0, < 3.7.15+5 more2023-09-22
CVE-2023-23766 [MEDIUM] CWE-697 CVE-2023-23766: An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request. To do so, an attacker would need write access to the repository. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.6.17, 3.7.15, 3.8
nvd
CVE-2023-6802P3MEDIUMCVSS 6.5≥ 3.8.0, < 3.8.12≥ 3.9.0, < 3.9.7+6 more2023-12-21
CVE-2023-6802 [MEDIUM] CWE-532 CVE-2023-6802: An insertion of sensitive information into the log file in the audit log in GitHub Enterprise Server
An insertion of sensitive information into the log file in the audit log in GitHub Enterprise Server was identified that could allow an attacker to gain access to the management console. To exploit this, an attacker would need access to the log files for the GitHub Enterprise Server appliance, a backup archive created with GitHub Enterprise Server Bac
nvd
CVE-2024-6337P3MEDIUMCVSS 6.5≥ 3.10.0, < 3.10.16≥ 3.11.0, < 3.11.14+2 more2024-08-20
CVE-2024-6337 [MEDIUM] CWE-863 CVE-2024-6337: An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a G
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only content: read and pull_request_write: write permissions to read issue content inside a private repository. This was only exploitable via user access token and installation access token was not impacted. This vulnerability affected al
nvd
CVE-2021-22867P3MEDIUMCVSS 6.5fixed in 2.22.17≥ 3.0.0, < 3.0.11+1 more2021-07-14
CVE-2021-22867 [MEDIUM] CWE-77 CVE-2021-22867: A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited wh
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read files on the GitHub Enterprise Server instance. To exploit this vulnerability, an attacker would n
nvd
CVE-2021-22870P3MEDIUMCVSS 6.5fixed in 3.0.19≥ 3.1.0, < 3.1.11+1 more2021-11-10
CVE-2021-22870 [MEDIUM] CWE-23 CVE-2021-22870: A path traversal vulnerability was identified in GitHub Pages builds on GitHub Enterprise Server tha
A path traversal vulnerability was identified in GitHub Pages builds on GitHub Enterprise Server that could allow an attacker to read system files. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterp
nvd
CVE-2023-22380P3MEDIUMCVSS 6.5≥ 3.7.0, < 3.7.62023-02-16
CVE-2023-22380 [MEDIUM] CWE-22 CVE-2023-22380: A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary fil
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterpris
nvd
CVE-2024-1908P3MEDIUMCVSS 6.5fixed in 3.8.16≥ 3.9.0, < 3.9.11+3 more2024-03-21
CVE-2024-1908 [MEDIUM] CWE-269 CVE-2024-1908: An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allow
An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use the Enterprise Actions GitHub Connect download token to fetch private repository data. An attacker would require an account on the server instance with non-default settings for GitHub Connect. This vulnerability affected all versio
nvd
CVE-2024-5566P3MEDIUMCVSS 6.5≥ 3.9.0, < 3.9.17≥ 3.10.0, < 3.10.14+3 more2024-07-16
CVE-2024-5566 [MEDIUM] CWE-269 CVE-2024-5566: An improper privilege management vulnerability allowed users to migrate private repositories without
An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes defined on the related Personal Access Token. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in version 3.13.1, 3.12.6, 3.11.12, 3.10.14, and 3.9.17.
nvd
CVE-2026-8606P3MEDIUMCVSS 5.9fixed in 3.16.19≥ 3.17.0, < 3.17.16+10 more2026-05-27
CVE-2026-8606 [MEDIUM] CWE-918 CVE-2026-8606: A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that a
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to internal services via the security advisories package lookup feature. By directing requests to an internal management service and measuring response timing, an attacker could infer the val
nvd
CVE-2024-10001P3HIGHCVSS 7.1fixed in 3.11.6≥ 3.12.0, < 3.12.10+7 more2025-01-29
CVE-2024-10001 [HIGH] CWE-94 CVE-2024-10001: A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to
A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious code into the query selector via the identity property in the message handling function. This enabled the exfiltration of sensitive data by manipulating the DOM, including authentication tokens. To execute the attack, the victim must be l
nvd
CVE-2022-23737P3MEDIUMCVSS 6.5fixed in 3.2.20≥ 3.3.0, < 3.3.15+3 more2022-12-01
CVE-2022-23737 [MEDIUM] CWE-269 CVE-2022-23737: An improper privilege management vulnerability was identified in GitHub Enterprise Server that allow
An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privileges to create or delete pages via the API. To exploit this vulnerability, an attacker would need to be added to an organization's repo with write permissions. This vulnerability affected all versions of GitHub Enterprise
nvd
CVE-2023-23765P3MEDIUMCVSS 6.5≥ 3.6.0, < 3.6.16≥ 3.7.0, < 3.7.13+3 more2023-08-30
CVE-2023-23765 [MEDIUM] CWE-697 CVE-2023-23765: An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request. To exploit this vulnerability, an attacker would need write access to the repository. This vulnerability was reported via the GitHub Bug Bounty Program https://bounty.github.com/
nvd
CVE-2022-46258P3MEDIUMCVSS 6.5fixed in 3.3.16≥ 3.4.0, < 3.4.11+2 more2023-01-09
CVE-2022-46258 [MEDIUM] CWE-863 CVE-2022-46258: An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a r
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository-scoped token with read/write access to modify Action Workflow files without a Workflow scope. The Create or Update file contents API should enforce workflow scope. This vulnerability affected all versions of GitHub Enterprise Server prior to
nvd
CVE-2024-8810P3MEDIUMCVSS 6.5≥ 3.10.0, < 3.10.17≥ 3.11.0, < 3.11.15+8 more2024-11-07
CVE-2024-8810 [MEDIUM] CWE-269 CVE-2024-8810: A GitHub App installed in organizations could upgrade some permissions from read to write access wit
A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from an organization administrator. An attacker would require an account with administrator access to install a malicious GitHub App. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versi
nvd
CVE-2025-3246P3HIGHCVSS 7.6v3.16.12025-04-17
CVE-2025-3246 [HIGH] CWE-79 CVE-2025-3246: An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that al
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting in GitHub Markdown that used `$$..$$` math blocks. Exploitation required access to the target GitHub Enterprise Server instance and privileged user interaction with the malicious elements. This vulnerability affected version 3.16
nvd