cbcvebase.

Github Enterprise Server vulnerabilities

127 known vulnerabilities affecting github/enterprise_server.

Total CVEs
127
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL20HIGH39MEDIUM64LOW4

Vulnerabilities

Page 7 of 7
CVE-2025-6600P4MEDIUMCVSS 4.3≥ 3.17.0, < 3.17.22025-07-01
CVE-2025-6600 [MEDIUM] CWE-200 CVE-2025-6600: An exposure of sensitive information vulnerability was identified in GitHub Enterprise Server that c An exposure of sensitive information vulnerability was identified in GitHub Enterprise Server that could allow an attacker to disclose the names of private repositories within an organization. This issue could be exploited by leveraging a user-to-server token with no scopes via the Search API endpoint. Successful exploitation required an organization
nvd
CVE-2024-2748P4MEDIUMCVSS 4.3v3.12.0≥ 3.12, ≤ 3.12.02024-03-21
CVE-2024-2748 [MEDIUM] CWE-352 CVE-2024-2748: A Cross Site Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed a A Cross Site Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker to execute unauthorized actions on behalf of an unsuspecting user. A mitigating factor is that user interaction is required. This vulnerability affected GitHub Enterprise Server 3.12.0 and was fixed in versions 3.12.1. This vulnerability was
nvd
CVE-2026-3307P4LOWCVSS 2.7fixed in 3.14.26≥ 3.15.0, < 3.15.21+12 more2026-04-21
CVE-2026-3307 [LOW] CWE-639 CVE-2026-3307: An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an att An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin access on one repository to modify the secret scanning push protection delegated bypass reviewer list on another repository by manipulating the owner_id parameter in the request body. Authorization was verified against the repository in th
nvd
CVE-2023-6803P4MEDIUMCVSS 4.0≥ 3.8.0, < 3.8.12≥ 3.9.0, < 3.9.7+6 more2023-12-21
CVE-2023-6803 [MEDIUM] CWE-367 CVE-2023-6803: A race condition in GitHub Enterprise Server allows an outside collaborator to be added while a repo A race condition in GitHub Enterprise Server allows an outside collaborator to be added while a repository is being transferred. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.
nvd
CVE-2024-8263P4LOWCVSS 2.7≥ 3.10.0, < 3.10.17≥ 3.11.0, < 3.11.15+3 more2024-09-23
CVE-2024-8263 [LOW] CWE-269 CVE-2024-8263: An improper privilege management vulnerability allowed arbitrary workflows to be committed using an An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty progr
nvd
CVE-2025-8447P4LOWCVSS 3.1fixed in 3.14.17≥ 3.15.0, < 3.15.12+6 more2025-08-26
CVE-2025-8447 [LOW] CWE-639 CVE-2025-8447: An improper access control vulnerability was identified in GitHub Enterprise Server that allowed use An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any repository to retrieve limited code content from another repository by creating a diff between the repositories. To exploit this vulnerability, an attacker needed to know the name of a private repository along with its branches, tags,
nvd
CVE-2023-6690P4LOWCVSS 2.0≥ 3.8.0, < 3.8.12≥ 3.9.0, < 3.9.7+6 more2023-12-21
CVE-2023-6690 [LOW] CWE-367 CVE-2023-6690: A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on tr A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphQL mutation to alter repository permissions during the transfer. This vulnerability affected GitHub Enterprise Server version 3.8.0 and above and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.
nvd
Github Enterprise Server vulnerabilities | cvebase