CVE-2024-5795
- EPSS 0.3%
- Veröffentlicht 16.07.2024 22:15:05
- Zuletzt bearbeitet 21.11.2024 09:48:20
A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause unbounded resource exhaustion by sending a large payload to the Git server. This vulnerability affected all versions of GitHub Enterprise S...
CVE-2024-5815
- EPSS 0.16%
- Veröffentlicht 16.07.2024 22:15:05
- Zuletzt bearbeitet 21.11.2024 09:48:23
A Cross-Site Request Forgery vulnerability in GitHub Enterprise Server allowed write operations on a victim-owned repository by exploiting incorrect request types. A mitigating factor is that the attacker would have to be a trusted GitHub Enterprise ...
CVE-2024-5817
- EPSS 0.3%
- Veröffentlicht 16.07.2024 22:15:05
- Zuletzt bearbeitet 21.11.2024 09:48:23
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed read access to issue content via GitHub Projects. This was only exploitable in internal repositories and required the attacker to have access to the corr...
CVE-2024-6336
- EPSS 0.28%
- Veröffentlicht 16.07.2024 22:15:05
- Zuletzt bearbeitet 21.11.2024 09:49:27
A Security Misconfiguration vulnerability in GitHub Enterprise Server allowed sensitive information disclosure to unauthorized users in GitHub Enterprise Server by exploiting organization ruleset feature. This attack required an organization member t...
CVE-2024-5566
- EPSS 0.2%
- Veröffentlicht 16.07.2024 22:15:04
- Zuletzt bearbeitet 21.11.2024 09:47:56
An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes defined on the related Personal Access Token. This vulnerability affected all versions of GitHub Enterprise Server prior to...
CVE-2024-5746
- EPSS 0.12%
- Veröffentlicht 20.06.2024 22:15:16
- Zuletzt bearbeitet 27.08.2025 20:54:48
A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the Site Administrator role to gain arbitrary code execution capability on the GitHub Enterprise Server instance. Exploitation requir...
CVE-2024-4985
- EPSS 0.4%
- Veröffentlicht 20.05.2024 22:15:08
- Zuletzt bearbeitet 27.08.2025 20:53:04
An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional encrypted assertions feature. This vulnerability allowed an attacker to forge a SAML respons...
CVE-2024-2440
- EPSS 0.14%
- Veröffentlicht 19.04.2024 17:15:54
- Zuletzt bearbeitet 02.09.2025 18:49:43
A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on a detached repository by making a GraphQL mutation to alter repository permissions while the repository is detached. This vulnerability affected all ver...
CVE-2024-3684
- EPSS 0.71%
- Veröffentlicht 19.04.2024 15:15:51
- Zuletzt bearbeitet 02.09.2025 18:53:29
A server side request forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin access to the appliance when configuring the Artifacts & Logs and Migrations S...
CVE-2024-3646
- EPSS 0.47%
- Veröffentlicht 19.04.2024 15:15:51
- Zuletzt bearbeitet 02.09.2025 19:04:42
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the instance when configuring the chat integration. Exploitation of this v...