Github

Enterprise Server

130 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 17.07.2026 15:20:23
  • Zuletzt bearbeitet 17.07.2026 18:11:59

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from private repositories they did not have access to, including private reposito...

  • EPSS 0.45%
  • Veröffentlicht 17.07.2026 15:18:46
  • Zuletzt bearbeitet 17.07.2026 18:11:59

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository paths, including GitHub Actions workflow files un...

  • EPSS 0.37%
  • Veröffentlicht 17.07.2026 15:16:02
  • Zuletzt bearbeitet 17.07.2026 18:11:59

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply nested YAML. When release notes w...

  • EPSS 0.26%
  • Veröffentlicht 01.07.2026 21:03:00
  • Zuletzt bearbeitet 06.07.2026 17:17:56

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories outside the token's intended scope....

  • EPSS 0.29%
  • Veröffentlicht 30.06.2026 21:39:02
  • Zuletzt bearbeitet 02.07.2026 15:33:48

A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary JavaScript in another user's browser by injecting a crafted payload into the title of a Discussion in t...

  • EPSS 0.28%
  • Veröffentlicht 30.06.2026 20:23:37
  • Zuletzt bearbeitet 02.07.2026 15:35:27

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private repositories they did not have access to. The Copilot pull request description diff summary endpoi...

  • EPSS 0.21%
  • Veröffentlicht 30.06.2026 20:21:12
  • Zuletzt bearbeitet 02.07.2026 15:41:11

A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application reques...

Medienbericht
  • EPSS 6.55%
  • Veröffentlicht 27.05.2026 00:16:39
  • Zuletzt bearbeitet 23.07.2026 11:10:00

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By...

  • EPSS 0.39%
  • Veröffentlicht 27.05.2026 00:16:37
  • Zuletzt bearbeitet 23.07.2026 11:10:00

A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to internal services via the security advisories package lookup feature. By directing re...

  • EPSS 0.16%
  • Veröffentlicht 07.05.2026 21:18:59
  • Zuletzt bearbeitet 11.05.2026 17:12:47

A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential theft. The redirect_to query parameter on the /setup/unlock endpoint was reflected into an HTML attribut...