GitHub / Github Enterprise Server
46 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-6600 | GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Search API | MEDIUM | 6.3 | Jul 1, 2025 |
| CVE-2025-3246 | Markdown math block sanitization bypass allows privilege escalation and unauthorized workflow triggers | HIGH | 8.6 | Apr 17, 2025 |
| CVE-2024-9539 | An information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allowing the attacker to retrieve metadata i… | MEDIUM | 5.7 | Oct 11, 2024 |
| CVE-2024-8263 | An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This… | MEDIUM | 6.2 | Sep 23, 2024 |
| CVE-2024-8770 | A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensi… | MEDIUM | 5.8 | Sep 23, 2024 |
| CVE-2024-6800 | An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizin… | CRITICAL | 9.5 | Aug 20, 2024 |
| CVE-2024-6337 | Incorrect Authorization allows read access to issues in GitHub Enterprise Server | MEDIUM | 5.9 | Aug 20, 2024 |
| CVE-2024-7711 | An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, and labels of any iss… | MEDIUM | 5.3 | Aug 20, 2024 |
| CVE-2024-6395 | GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Deploy Keys | MEDIUM | 6.3 | Jul 16, 2024 |
| CVE-2024-6336 | Security misconfiguration was identified in GitHub Enterprise Server that allowed sensitive data exposure | MEDIUM | 6.9 | Jul 16, 2024 |
| CVE-2024-5817 | Improper authorization allows read access to issue content in GitHub Enterprise Server | MEDIUM | 5.9 | Jul 16, 2024 |
| CVE-2024-5816 | Improper authorization allows persistent access in GitHub Enterprise Server | MEDIUM | 6.9 | Jul 16, 2024 |
| CVE-2024-5815 | Cross Site Request Forgery was identified in GitHub Enterprise Server that allowed write in a user owned repository | MEDIUM | 6.8 | Jul 16, 2024 |
| CVE-2024-5795 | Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed resource exhaustion | HIGH | 7.7 | Jul 16, 2024 |
| CVE-2024-5566 | Improper Privilege Management allows for access to unauthorized repository content during migration | MEDIUM | 6.5 | Jul 16, 2024 |
| CVE-2024-5746 | A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the Site Administrator role to gain arbitr… | HIGH | 7.6 | Jun 20, 2024 |
| CVE-2024-2443 | Improper input validation vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console | CRITICAL | 9.1 | Mar 20, 2024 |
| CVE-2022-46257 | Information disclosure in GitHub Enterprise Server leading to unauthorized viewing of private repository names | MEDIUM | 4.3 | Mar 7, 2023 |
| CVE-2023-22380 | Path traversal in GitHub Enterprise Server leading to arbitrary file reading when building a GitHub Pages site | MEDIUM | 6.5 | Feb 16, 2023 |
| CVE-2022-23739 | Incorrect authorization check in GitHub Enterprise Server leading to escalation of privileges in GraphQL API requests from GitHub Apps using scoped user-to-ser… | CRITICAL | 9.8 | Jan 17, 2023 |
| CVE-2022-46258 | Incorrect Authorization in GitHub Enterprise Server leads to Action Workflow modifications without Workflow Scope | MEDIUM | 6.5 | Jan 9, 2023 |
| CVE-2022-46256 | Path traversal in GitHub Enterprise Server leading to remote code execution in GitHub Pages | HIGH | 8.8 | Dec 14, 2022 |
| CVE-2022-46255 | Improper Limitation of a Pathname to a Restricted Directory in GitHub Enterprise Server leading to RCE | CRITICAL | 9.8 | Dec 14, 2022 |
| CVE-2022-23741 | Incorrect authorization in GitHub Enterprise Server token generation leading to full admin access | HIGH | 7.2 | Dec 14, 2022 |
| CVE-2022-23737 | Improper Privilege Management in GitHub Enterprise Server leading to page creation and deletion | MEDIUM | 6.5 | Dec 1, 2022 |
Showing 1 to 25 of 46 CVEs