Github

Enterprise Server

111 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 07.05.2026 21:18:59
  • Zuletzt bearbeitet 11.05.2026 17:12:47

A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential theft. The redirect_to query parameter on the /setup/unlock endpoint was reflected into an HTML attribut...

  • EPSS 0.06%
  • Veröffentlicht 07.05.2026 21:18:49
  • Zuletzt bearbeitet 11.05.2026 17:18:27

A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting URL parser confusion between the validation layer and the HTTP reques...

  • EPSS 0.06%
  • Veröffentlicht 07.05.2026 21:18:35
  • Zuletzt bearbeitet 11.05.2026 17:19:36

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by sending crafted requests with deeply nested JSON payloads to an unauthenticated API endpoint. The end...

  • EPSS 0.17%
  • Veröffentlicht 07.05.2026 21:14:33
  • Zuletzt bearbeitet 11.05.2026 17:20:51

An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to create a local user account, bypassing the configured external identity provider. When external authentication was enabled, ...

  • EPSS 0.02%
  • Veröffentlicht 21.04.2026 22:42:13
  • Zuletzt bearbeitet 29.04.2026 12:30:18

An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attacker to access private repositories outside the intended installation scope, which can include write o...

  • EPSS 0.04%
  • Veröffentlicht 21.04.2026 22:23:25
  • Zuletzt bearbeitet 29.04.2026 12:47:57

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin access on one repository to modify the secret scanning push protection delegated bypass reviewer list on another repository by manipu...

  • EPSS 0.03%
  • Veröffentlicht 21.04.2026 22:12:58
  • Zuletzt bearbeitet 29.04.2026 12:35:08

An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to determine the names of private repositories by their numeric ID. The mobile upload policy API endpoint did not perform an ear...

  • EPSS 0.04%
  • Veröffentlicht 21.04.2026 22:12:45
  • Zuletzt bearbeitet 29.04.2026 12:39:18

An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI validation. An attacker with knowledge of a first-party OAuth application's registered callback URL could c...

  • EPSS 0.04%
  • Veröffentlicht 21.04.2026 22:12:26
  • Zuletzt bearbeitet 29.04.2026 12:36:27

An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Management Console administrator to execute arbitrary OS commands via shell metacharacter injection in proxy configu...

  • EPSS 0.07%
  • Veröffentlicht 21.04.2026 22:11:02
  • Zuletzt bearbeitet 28.04.2026 20:43:12

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract sensitive environment variables from the instance through a timing side-channel attack against the notebook rendering se...