VYPR

Enterprise Server

by GitHub

CVEs (128)

  • CVE-2023-46649MedDec 21, 2023
    risk 0.41cvss 6.3epss 0.00

    A race condition in GitHub Enterprise Server was identified that could allow an attacker administrator access. To exploit this, an organization needs to be converted from a user. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in…

  • CVE-2026-8106MedMay 7, 2026
    risk 0.40cvss 6.1epss 0.00

    A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential theft. The redirect_to query parameter on the /setup/unlock endpoint was reflected into an HTML attribute without proper…

  • CVE-2025-14046MedDec 11, 2025
    risk 0.40cvss 6.1epss 0.00

    An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied HTML to inject DOM elements with IDs that collided with server-initialized data islands. These collisions could overwrite or shadow critical application state…

  • CVE-2024-8770MedSep 23, 2024
    risk 0.40cvss 6.1epss 0.00

    A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via social engineering. This vulnerability affected all versions of GitHub Enterprise Server and…

  • CVE-2026-8606MedMay 27, 2026
    risk 0.38cvss 5.9epss 0.00

    A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to internal services via the security advisories package lookup feature. By directing requests to an internal…

  • CVE-2024-5566MedJul 16, 2024
    risk 0.38cvss 5.8epss 0.00

    An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes defined on the related Personal Access Token. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in…

  • CVE-2024-3470MedApr 19, 2024
    risk 0.38cvss 5.9epss 0.01

    An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use a deploy key pertaining to an organization to bypass an organization ruleset. An attacker would require access to a valid deploy key for a repository in the…

  • CVE-2023-6803MedDec 21, 2023
    risk 0.38cvss 5.8epss 0.00

    A race condition in GitHub Enterprise Server allows an outside collaborator to be added while a repository is being transferred. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.

  • CVE-2022-23738MedNov 1, 2022
    risk 0.37cvss 5.7epss 0.01

    An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to access private repository files through a public repository. To exploit this, an actor would need to already be authorized on the GitHub Enterprise Server…

  • CVE-2024-2440MedApr 19, 2024
    risk 0.36cvss 5.5epss 0.00

    A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on a detached repository by making a GraphQL mutation to alter repository permissions while the repository is detached. This vulnerability affected all versions of GitHub Enterprise…

  • CVE-2026-2266MedMar 10, 2026
    risk 0.35cvss 5.4epss 0.00

    An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed DOM-based cross-site scripting via task list content. The task list content extraction logic did not properly re-encode browser-decoded text nodes before rendering, allowing…

  • CVE-2025-13744MedJan 6, 2026
    risk 0.35cvss 5.4epss 0.00

    An Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server that allowed attacker controlled HTML to be rendered by the Filter component (search) across GitHub that could be used to exfiltrate sensitive information. An…

  • CVE-2022-23733MedAug 2, 2022
    risk 0.35cvss 5.4epss 0.01

    A stored XSS vulnerability was identified in GitHub Enterprise Server that allowed the injection of arbitrary attributes. This injection was blocked by Github's Content Security Policy (CSP). This vulnerability affected all versions of GitHub Enterprise Server prior to 3.6 and…

  • CVE-2024-6395MedJul 16, 2024
    risk 0.34cvss 5.3epss 0.00

    An exposure of sensitive information vulnerability in GitHub Enterprise Server would allow an attacker to enumerate the names of private repositories that utilize deploy keys. This vulnerability did not allow unauthorized access to any repository content besides the name. This…

  • CVE-2024-6336MedJul 16, 2024
    risk 0.34cvss 5.3epss 0.00

    A Security Misconfiguration vulnerability in GitHub Enterprise Server allowed sensitive information disclosure to unauthorized users in GitHub Enterprise Server by exploiting organization ruleset feature. This attack required an organization member to explicitly change the…

  • CVE-2024-5816MedJul 16, 2024
    risk 0.34cvss 5.3epss 0.01

    An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App to retain access to the repository via a scoped user access token. This was only exploitable in public repositories while private repositories were not…

  • CVE-2023-46646MedDec 21, 2023
    risk 0.34cvss 5.3epss 0.01

    Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get a check run" API endpoint. This vulnerability did not allow unauthorized access to any repository content besides the name. This…

  • CVE-2023-23763MedSep 1, 2023
    risk 0.34cvss 5.3epss 0.01

    An authorization/sensitive information disclosure vulnerability was identified in GitHub Enterprise Server that allowed a fork to retain read access to an upstream repository after its visibility was changed to private. This vulnerability affected all versions of GitHub…

  • CVE-2023-51379MedDec 21, 2023
    risk 0.32cvss 4.9epss 0.01

    An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be updated with an improperly scoped token. This vulnerability did not allow unauthorized access to any repository content as it also required contents:write and…

  • CVE-2023-23760MedMar 8, 2023
    risk 0.32cvss 4.9epss 0.01

    A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise…

Page 5 of 7