CVE-2025-8447
- EPSS 0.03%
- Veröffentlicht 26.08.2025 01:42:37
- Zuletzt bearbeitet 03.09.2025 17:42:50
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any repository to retrieve limited code content from another repository by creating a diff between the repositories. To exploit this...
CVE-2025-6981
- EPSS 0.04%
- Veröffentlicht 15.07.2025 20:44:30
- Zuletzt bearbeitet 27.08.2025 14:41:04
An incorrect authorization vulnerability allowed unauthorized read access to the contents of internal repositories for contractor accounts when the Contractors API feature was enabled. The Contractors API is a rarely-enabled feature in private previe...
CVE-2025-6600
- EPSS 0.03%
- Veröffentlicht 01.07.2025 18:56:45
- Zuletzt bearbeitet 05.09.2025 14:59:47
An exposure of sensitive information vulnerability was identified in GitHub Enterprise Server that could allow an attacker to disclose the names of private repositories within an organization. This issue could be exploited by leveraging a user-to-ser...
CVE-2025-3246
- EPSS 0.03%
- Veröffentlicht 17.04.2025 22:50:22
- Zuletzt bearbeitet 05.09.2025 15:00:02
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting in GitHub Markdown that used `$$..$$` math blocks. Exploitation required access to the target GitHub Enterprise Server ins...
CVE-2025-3509
- EPSS 0.37%
- Veröffentlicht 17.04.2025 22:50:18
- Zuletzt bearbeitet 05.09.2025 14:59:50
A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute arbitrary code by exploiting the pre-receive hook functionality, potentially leading to privilege escalation and system compromis...
CVE-2025-3124
- EPSS 0.04%
- Veröffentlicht 17.04.2025 22:50:14
- Zuletzt bearbeitet 05.09.2025 15:00:04
A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise have access to in the Security Overview in GitHub Advanced Security. The Securi...
CVE-2024-10001
- EPSS 0.13%
- Veröffentlicht 29.01.2025 19:15:18
- Zuletzt bearbeitet 05.09.2025 15:00:06
A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious code into the query selector via the identity property in the message handling function. This enabled the exfiltration of sensitive d...
CVE-2025-23369
- EPSS 9.49%
- Veröffentlicht 21.01.2025 19:15:12
- Zuletzt bearbeitet 05.09.2025 15:00:09
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed signature spoofing for unauthorized internal users. Instances not utilizing SAML single sign-on or where the attacker is not al...
CVE-2024-8810
- EPSS 0.13%
- Veröffentlicht 07.11.2024 22:15:21
- Zuletzt bearbeitet 27.08.2025 16:33:25
A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from an organization administrator. An attacker would require an account with administrator access to install a malicious GitHub App. Th...
CVE-2024-10824
- EPSS 0.11%
- Veröffentlicht 07.11.2024 22:15:20
- Zuletzt bearbeitet 27.08.2025 16:27:58
An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauthorized internal users to access sensitive secret scanning alert data intended only for business owners. This issue could be exploited only by organiza...