Github

Enterprise Server

101 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 10.03.2026 18:56:56
  • Zuletzt bearbeitet 12.03.2026 18:42:24

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with a classic personal access token (PAT) lacking the repo scope to retrieve issues and commits from private and internal reposito...

  • EPSS 0.03%
  • Veröffentlicht 10.03.2026 18:55:38
  • Zuletzt bearbeitet 12.03.2026 18:43:27

An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed DOM-based cross-site scripting via task list content. The task list content extraction logic did not properly re-encode browser-decoded text nod...

  • EPSS 0.02%
  • Veröffentlicht 10.03.2026 17:46:57
  • Zuletzt bearbeitet 12.03.2026 18:46:22

An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed a user with read access to a repository and write access to a project to modify issue and pull request metadata through the project. When adding an item t...

  • EPSS 0.34%
  • Veröffentlicht 10.03.2026 17:37:34
  • Zuletzt bearbeitet 12.03.2026 18:45:25

An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote code execution on the instance. During a git push operation, user-supp...

  • EPSS 0.03%
  • Veröffentlicht 18.02.2026 20:44:51
  • Zuletzt bearbeitet 03.03.2026 16:16:19

A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to access internal services bound to loopback or unspecified addresses, potentially disrupting background job processing,...

  • EPSS 0.16%
  • Veröffentlicht 18.02.2026 20:42:07
  • Zuletzt bearbeitet 19.02.2026 22:08:57

A Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to upload unauthorized content to another user’s repository migration export due to a missing authorization check in the repository migration up...

  • EPSS 0.06%
  • Veröffentlicht 18.02.2026 20:37:39
  • Zuletzt bearbeitet 19.02.2026 22:49:21

An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sensitive authorization tokens. The repository_pages API insecurely followed HTTP redirects when fetching artifact URLs, pr...

  • EPSS 0.04%
  • Veröffentlicht 06.01.2026 20:44:02
  • Zuletzt bearbeitet 30.01.2026 16:51:10

An Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server that allowed attacker controlled HTML to be rendered by the Filter component (search) across GitHub that could be used to exfiltra...

  • EPSS 0.04%
  • Veröffentlicht 11.12.2025 17:52:05
  • Zuletzt bearbeitet 19.12.2025 19:47:36

An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied HTML to inject DOM elements with IDs that collided with server-initialized data islands. These collisions could overwrite or shado...

  • EPSS 0.15%
  • Veröffentlicht 10.11.2025 22:44:33
  • Zuletzt bearbeitet 08.12.2025 18:22:46

A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH access to the appliance by exploiting a symlink escape in pre-receive hook environments. By crafting a mal...