cbcvebase.

Github Enterprise Server vulnerabilities

127 known vulnerabilities affecting github/enterprise_server.

Total CVEs
127
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL20HIGH39MEDIUM64LOW4

Vulnerabilities

Page 5 of 7
CVE-2021-22865P3MEDIUMCVSS 6.5fixed in 2.21.18≥ 2.22.0, < 2.22.10+1 more2021-04-02
CVE-2021-22865 [MEDIUM] CWE-285 CVE-2021-22865: An improper access control vulnerability was identified in GitHub Enterprise Server that allowed acc An improper access control vulnerability was identified in GitHub Enterprise Server that allowed access tokens generated from a GitHub App's web authentication flow to read private repository metadata via the REST API without having been granted the appropriate permissions. To exploit this vulnerability, an attacker would need to create a GitHub App
nvd
CVE-2026-15007P3MEDIUMCVSS 5.7≥ 3.17.0, ≤ 3.17.17≥ 3.18.0, ≤ 3.18.11+3 more2026-07-17
CVE-2026-15007 [MEDIUM] CWE-770 CVE-2026-15007: A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authent A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply nested YAML. When release notes were generated, the configuration file was parsed without a nesting depth limit, causing excessive res
nvd
CVE-2026-15783P3MEDIUMCVSS 5.3≥ 3.17.0, ≤ 3.17.17≥ 3.18.0, ≤ 3.18.11+3 more2026-07-17
CVE-2026-15783 [MEDIUM] CWE-862 CVE-2026-15783: A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an aut A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from private repositories they did not have access to, including private repository owners and names, branch names, commit SHAs, commit messages, and the pushing actor. The delegated
nvd
CVE-2023-46649P3HIGHCVSS 7.0≥ 3.7.0, < 3.7.19≥ 3.8.0, < 3.8.12+8 more2023-12-21
CVE-2023-46649 [HIGH] CWE-367 CVE-2023-46649: A race condition in GitHub Enterprise Server was identified that could allow an attacker administrat A race condition in GitHub Enterprise Server was identified that could allow an attacker administrator access. To exploit this, an organization needs to be converted from a user. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.7.19, 3.8.12, 3.9.7, 3.10.4, and 3.11.1.
nvd
CVE-2026-103620P3MEDIUMCVSS 6.0≥ 3.18.0, < 3.18.*≥ 3.19.0, < 3.19.*+3 more2026-10-06
CVE-2026-103620 [MEDIUM] CWE-862 CVE-2026-103620: A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a repo A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository collaborator with write access to delete the current default branch through the GraphQL API and cause an attacker-controlled branch to become the new default. In repositories that required pull-request review but did not restrict branch delet
nvd
CVE-2024-5795P3MEDIUMCVSS 6.5≥ 3.9.0, < 3.9.17≥ 3.10.0, < 3.10.14+3 more2024-07-16
CVE-2024-5795 [MEDIUM] CWE-400 CVE-2024-5795: A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacke A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause unbounded resource exhaustion by sending a large payload to the Git server. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in version 3.13.1, 3.12.6, 3.11.12, 3.10.14, and 3.9.17. This vulnera
nvd
CVE-2024-2440P4MEDIUMCVSS 5.9fixed in 3.9.13≥ 3.10.0, < 3.10.10+6 more2024-04-19
CVE-2024-2440 [MEDIUM] CWE-367 CVE-2024-2440: A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on a A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on a detached repository by making a GraphQL mutation to alter repository permissions while the repository is detached. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.13 and was fixed in versions 3.9.13, 3.10.10, 3.11.8 and 3.
nvd
CVE-2024-5815P4MEDIUMCVSS 6.5≥ 3.9.0, < 3.9.17≥ 3.10.0, < 3.10.14+3 more2024-07-16
CVE-2024-5815 [MEDIUM] CWE-352 CVE-2024-5815: A Cross-Site Request Forgery vulnerability in GitHub Enterprise Server allowed write operations on a A Cross-Site Request Forgery vulnerability in GitHub Enterprise Server allowed write operations on a victim-owned repository by exploiting incorrect request types. A mitigating factor is that the attacker would have to be a trusted GitHub Enterprise Server user, and the victim would have to visit a tag in the attacker's fork of their own repository. v
nvd
CVE-2023-23762P4MEDIUMCVSS 5.3fixed in 3.4.18≥ 3.5.0, < 3.5.15+8 more2023-04-07
CVE-2023-23762 [MEDIUM] CWE-697 CVE-2023-23762: An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff. To do so, an attacker would need write access to the repository and be able to correctly guess the target branch before it’s created by the code maintainer. This vulnerability affected all versions of GitHub
nvd
CVE-2025-14046P4MEDIUMCVSS 6.1fixed in 3.14.21≥ 3.15.0, < 3.15.16+8 more2025-12-11
CVE-2025-14046 [MEDIUM] CWE-79 CVE-2025-14046: An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that al An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied HTML to inject DOM elements with IDs that collided with server-initialized data islands. These collisions could overwrite or shadow critical application state objects used by certain Project views, leading to unintended server-side
nvd
CVE-2022-23738P4MEDIUMCVSS 5.7≥ 3.2.0, < 3.2.20≥ 3.3.0, < 3.3.15+3 more2022-11-01
CVE-2022-23738 [MEDIUM] CWE-200 CVE-2022-23738: An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unaut An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to access private repository files through a public repository. To exploit this, an actor would need to already be authorized on the GitHub Enterprise Server instance, be able to create a public repository, and have a site administrator
nvd
CVE-2023-6746P4MEDIUMCVSS 5.7≥ 3.7.0, < 3.7.19≥ 3.8.0, < 3.8.12+8 more2023-12-21
CVE-2023-6746 [MEDIUM] CWE-532 CVE-2023-6746: An insertion of sensitive information into log file vulnerability was identified in the log files fo An insertion of sensitive information into log file vulnerability was identified in the log files for a GitHub Enterprise Server back-end service that could permit an `adversary in the middle attack` when combined with other phishing techniques. To exploit this, an attacker would need access to the log files for the GitHub Enterprise Server appliance,
nvd
CVE-2024-5816P4MEDIUMCVSS 5.3≥ 3.9.0, < 3.9.17≥ 3.10.0, < 3.10.14+3 more2024-07-16
CVE-2024-5816 [MEDIUM] CWE-863 CVE-2024-5816: An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a s An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App to retain access to the repository via a scoped user access token. This was only exploitable in public repositories while private repositories were not impacted. This vulnerability affected all versions of GitHub Enterprise Server pr
nvd
CVE-2023-23761P4MEDIUMCVSS 5.3fixed in 3.4.18≥ 3.5.0, < 3.5.15+8 more2023-04-07
CVE-2023-23761 [MEDIUM] CWE-287 CVE-2023-23761: An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed an An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to modify other users' secret gists by authenticating through an SSH certificate authority. To do so, a user had to know the secret gist's URL. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.9 and was
nvd
CVE-2026-14340P4MEDIUMCVSS 5.0fixed in 3.16.20≥ 3.17.0, < 3.17.17+10 more2026-07-01
CVE-2026-14340 [MEDIUM] CWE-863 CVE-2026-14340: An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a u An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories outside the token's intended scope. This was possible because the authorization check only verified that the installation had read permi
nvd
CVE-2026-8106P4MEDIUMCVSS 6.1≥ 3.19.1, < 3.19.6≥ 3.20.0, < 3.20.2+2 more2026-05-07
CVE-2026-8106 [MEDIUM] CWE-79 CVE-2026-8106: A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management C A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential theft. The redirect_to query parameter on the /setup/unlock endpoint was reflected into an HTML attribute without proper sanitization, enabling an attacker to inject a form element that could capture administ
nvd
CVE-2026-10585P4MEDIUMCVSS 5.4fixed in 3.16.20≥ 3.17.0, < 3.17.17+8 more2026-06-30
CVE-2026-10585 [MEDIUM] CWE-79 CVE-2026-10585: A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary JavaScript in another user's browser by injecting a crafted payload into the title of a Discussion in the Q&A category. The AnsweredQuestionStructuredDataComponent did not escape user-controlled Discussion
nvd
CVE-2023-46646P4MEDIUMCVSS 5.3≥ 3.7.0, < 3.7.19≥ 3.8.0, < 3.8.12+6 more2023-12-21
CVE-2023-46646 [MEDIUM] CWE-639 CVE-2023-46646: Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to vie Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get a check run" API endpoint. This vulnerability did not allow unauthorized access to any repository content besides the name. This vulnerability affected GitHub Enterprise Server version 3.7.0 and above and was fi
nvd
CVE-2024-6336P4MEDIUMCVSS 5.3≥ 3.9.0, < 3.9.17≥ 3.10.0, < 3.10.14+3 more2024-07-16
CVE-2024-6336 [MEDIUM] CWE-200 CVE-2024-6336: A Security Misconfiguration vulnerability in GitHub Enterprise Server allowed sensitive information A Security Misconfiguration vulnerability in GitHub Enterprise Server allowed sensitive information disclosure to unauthorized users in GitHub Enterprise Server by exploiting organization ruleset feature. This attack required an organization member to explicitly change the visibility of a dependent repository from private to public. This vulnerability
nvd
CVE-2023-46645P4MEDIUMCVSS 4.9≥ 3.7.0, < 3.7.19≥ 3.8.0, < 3.8.12+4 more2023-12-21
CVE-2023-46645 [MEDIUM] CWE-22 CVE-2023-46645: A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary fil A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterpris
nvd
Github Enterprise Server vulnerabilities | cvebase