VYPR

Enterprise Server

by GitHub

CVEs (134)

  • CVE-2021-22863HigMar 3, 2021
    risk 0.53cvss 8.1epss 0.01

    An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allowed authenticated users of the instance to modify the maintainer collaboration permission of a pull request without proper authorization. By exploiting this…

  • CVE-2024-3684HigApr 19, 2024
    risk 0.52cvss 8.0epss 0.01

    A server side request forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin access to the appliance when configuring the Artifacts & Logs and Migrations Storage. Exploitation of this…

  • CVE-2024-3646HigApr 19, 2024
    risk 0.52cvss 8.0epss 0.02

    A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the instance when configuring the chat integration. Exploitation of this vulnerability required access…

  • CVE-2024-2469HigMar 20, 2024
    risk 0.52cvss 8.0epss 0.02

    An attacker with an Administrator role in GitHub Enterprise Server could gain SSH root access via remote code execution. This vulnerability affected GitHub Enterprise Server version 3.8.0 and above and was fixed in version 3.8.17, 3.9.12, 3.10.9, 3.11.7 and 3.12.1. This…

  • CVE-2024-1354HigFeb 13, 2024
    risk 0.52cvss 8.0epss 0.02

    A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via the `syslog-ng` configuration file. Exploitation of this vulnerability required…

  • CVE-2023-46647HigDec 21, 2023
    risk 0.52cvss 8.0epss 0.01

    Improper privilege management in all versions of GitHub Enterprise Server allows users with authorized access to the management console with an editor role to escalate their privileges by making requests to the endpoint used for bootstrapping the instance. This vulnerability…

  • CVE-2024-5795HigJul 16, 2024
    risk 0.50cvss 7.7epss 0.01

    A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause unbounded resource exhaustion by sending a large payload to the Git server. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was…

  • CVE-2023-23761HigApr 7, 2023
    risk 0.50cvss 7.7epss 0.00

    An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to modify other users' secret gists by authenticating through an SSH certificate authority. To do so, a user had to know the secret gist's URL. This…

  • CVE-2026-19118HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.01

    A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticated user with write access to a repository and precise timing of concurrent upload requests. This…

  • CVE-2026-15996HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumption and exhaust the pool of request-handling worker processes by sending a crafted form-encoded HTTP POST request containing…

  • CVE-2026-7541HigMay 7, 2026
    risk 0.49cvss 7.5epss 0.00

    A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by sending crafted requests with deeply nested JSON payloads to an unauthenticated API endpoint. The endpoint parsed user-controlled…

  • CVE-2025-3246HigApr 17, 2025
    risk 0.49cvss 7.6epss 0.00

    An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting in GitHub Markdown that used `$$..$$` math blocks. Exploitation required access to the target GitHub Enterprise Server instance and privileged user…

  • CVE-2024-5746HigJun 20, 2024
    risk 0.49cvss 7.6epss 0.01

    A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the Site Administrator role to gain arbitrary code execution capability on the GitHub Enterprise Server instance. Exploitation required authenticated access to…

  • CVE-2023-6847HigDec 21, 2023
    risk 0.49cvss 7.5epss 0.01

    An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed a bypass of Private Mode by using a specially crafted API request. To exploit this vulnerability, an attacker would need network access to the Enterprise Server appliance configured…

  • CVE-2026-77912HigSep 22, 2026
    risk 0.48cvss —epss —

    A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrote quote characters in already-sanitized…

  • CVE-2026-18730HigSep 1, 2026
    risk 0.48cvss 7.4epss 0.00

    A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an attacker-controlled host. An unauthenticated endpoint parsed an…

  • CVE-2024-0507MedJan 16, 2024
    risk 0.48cvss 6.5epss 0.66

    An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.11.3,…

  • CVE-2025-11578HigNov 10, 2025
    risk 0.47cvss 7.2epss 0.01

    A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH access to the appliance by exploiting a symlink escape in pre-receive hook environments. By crafting a malicious repository and…

  • CVE-2025-3509HigApr 17, 2025
    risk 0.47cvss 7.2epss 0.01

    A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute arbitrary code by exploiting the pre-receive hook functionality, potentially leading to privilege escalation and system compromise. The vulnerability involves…

  • CVE-2023-6802HigDec 21, 2023
    risk 0.47cvss 7.2epss 0.01

    An insertion of sensitive information into the log file in the audit log in GitHub Enterprise Server was identified that could allow an attacker to gain access to the management console. To exploit this, an attacker would need access to the log files for the GitHub Enterprise…

Page 3 of 7