CVE-2023-23766
- EPSS 0.11%
- Published 22.09.2023 15:15:10
- Last modified 21.11.2024 07:46:47
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request. To do so, an attacker would need write access to the repository. This vulnerab...
CVE-2023-23763
- EPSS 0.11%
- Published 01.09.2023 15:15:07
- Last modified 21.11.2024 07:46:47
An authorization/sensitive information disclosure vulnerability was identified in GitHub Enterprise Server that allowed a fork to retain read access to an upstream repository after its visibility was changed to private. This vulnerability affected al...
CVE-2023-23765
- EPSS 0.08%
- Published 30.08.2023 23:15:08
- Last modified 21.11.2024 07:46:47
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request. To exploit this vulnerability, an attacker would need write access to the repo...
CVE-2023-23764
- EPSS 0.15%
- Published 27.07.2023 21:15:10
- Last modified 21.11.2024 07:46:47
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff within the GitHub pull request UI. To do so, an attacker would need write access to the repository. This vu...
CVE-2023-23762
- EPSS 0.13%
- Published 07.04.2023 19:15:07
- Last modified 21.11.2024 07:46:47
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff. To do so, an attacker would need write access to the repository and be able to correctly guess the target ...
CVE-2023-23761
- EPSS 0.07%
- Published 07.04.2023 19:15:06
- Last modified 21.11.2024 07:46:46
An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to modify other users' secret gists by authenticating through an SSH certificate authority. To do so, a user had to know the secret...
CVE-2023-23760
- EPSS 0.43%
- Published 08.03.2023 19:15:10
- Last modified 21.11.2024 07:46:46
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site o...
CVE-2022-46257
- EPSS 0.05%
- Published 07.03.2023 17:15:12
- Last modified 21.11.2024 07:30:17
An information disclosure vulnerability was identified in GitHub Enterprise Server that allowed private repositories to be added to a GitHub Actions runner group via the API by a user who did not have access to those repositories, resulting in the re...
CVE-2023-22381
- EPSS 0.12%
- Published 02.03.2023 21:15:10
- Last modified 21.11.2024 07:44:40
A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment variables from a single environment variable value in GitHub Actions when using a Windows based runner. To exploit this vulnerability...
CVE-2023-22380
- EPSS 0.1%
- Published 16.02.2023 21:15:14
- Last modified 19.03.2025 16:15:17
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site ...