CVE-2025-23369
- EPSS 9.97%
- Veröffentlicht 21.01.2025 19:15:12
- Zuletzt bearbeitet 05.09.2025 15:00:09
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed signature spoofing for unauthorized internal users. Instances not utilizing SAML single sign-on or where the attacker is not al...
CVE-2024-8810
- EPSS 0.06%
- Veröffentlicht 07.11.2024 22:15:21
- Zuletzt bearbeitet 27.08.2025 16:33:25
A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from an organization administrator. An attacker would require an account with administrator access to install a malicious GitHub App. Th...
CVE-2024-10824
- EPSS 0.04%
- Veröffentlicht 07.11.2024 22:15:20
- Zuletzt bearbeitet 27.08.2025 16:27:58
An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauthorized internal users to access sensitive secret scanning alert data intended only for business owners. This issue could be exploited only by organiza...
CVE-2024-10007
- EPSS 0.2%
- Veröffentlicht 07.11.2024 21:15:06
- Zuletzt bearbeitet 27.08.2025 16:32:40
A path collision and arbitrary code execution vulnerability was identified in GitHub Enterprise Server that allowed container escape to escalate to root via ghe-firejail path. Exploitation of this vulnerability requires Enterprise Administrator acces...
CVE-2024-9539
- EPSS 0.44%
- Veröffentlicht 11.10.2024 18:15:08
- Zuletzt bearbeitet 15.11.2024 17:15:06
An information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allowing the attacker to retrieve metadata information of a user who clicks on the URL and further exploit it to create a convincing ph...
CVE-2024-9487
- EPSS 55.49%
- Veröffentlicht 10.10.2024 22:15:11
- Zuletzt bearbeitet 15.11.2024 16:57:10
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning of users and access to the instance. Exploitation ...
CVE-2024-8770
- EPSS 0.23%
- Veröffentlicht 23.09.2024 21:15:13
- Zuletzt bearbeitet 27.09.2024 13:49:29
A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via social engineering. This vulnerability affected all versions of G...
CVE-2024-8263
- EPSS 0.09%
- Veröffentlicht 23.09.2024 21:15:12
- Zuletzt bearbeitet 30.09.2024 15:57:26
An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3....
CVE-2024-7711
- EPSS 0.28%
- Veröffentlicht 20.08.2024 20:15:10
- Zuletzt bearbeitet 27.09.2024 18:17:05
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, and labels of any issue inside a public repository. This was only exploitable inside a public repository. This v...
CVE-2024-6800
- EPSS 2.88%
- Veröffentlicht 20.08.2024 20:15:09
- Zuletzt bearbeitet 30.09.2024 19:14:50
An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed signed federation metadata XML. This vulnerability allowed an attacker w...