Github

Enterprise Server

93 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 20.08.2024 20:15:09
  • Zuletzt bearbeitet 27.09.2024 17:48:00

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only content: read and pull_request_write: write permissions to read issue content inside a private repository. This was only exploitab...

  • EPSS 0.61%
  • Veröffentlicht 16.07.2024 22:15:06
  • Zuletzt bearbeitet 21.11.2024 09:49:34

An exposure of sensitive information vulnerability in GitHub Enterprise Server would allow an attacker to enumerate the names of private repositories that utilize deploy keys. This vulnerability did not allow unauthorized access to any repository con...

  • EPSS 0.39%
  • Veröffentlicht 16.07.2024 22:15:05
  • Zuletzt bearbeitet 21.11.2024 09:49:27

A Security Misconfiguration vulnerability in GitHub Enterprise Server allowed sensitive information disclosure to unauthorized users in GitHub Enterprise Server by exploiting organization ruleset feature. This attack required an organization member t...

  • EPSS 0.3%
  • Veröffentlicht 16.07.2024 22:15:05
  • Zuletzt bearbeitet 21.11.2024 09:48:20

A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause unbounded resource exhaustion by sending a large payload to the Git server. This vulnerability affected all versions of GitHub Enterprise S...

  • EPSS 0.16%
  • Veröffentlicht 16.07.2024 22:15:05
  • Zuletzt bearbeitet 21.11.2024 09:48:23

A Cross-Site Request Forgery vulnerability in GitHub Enterprise Server allowed write operations on a victim-owned repository by exploiting incorrect request types. A mitigating factor is that the attacker would have to be a trusted GitHub Enterprise ...

  • EPSS 0.4%
  • Veröffentlicht 16.07.2024 22:15:05
  • Zuletzt bearbeitet 21.11.2024 09:48:23

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed read access to issue content via GitHub Projects. This was only exploitable in internal repositories and required the attacker to have access to the corr...

  • EPSS 1.15%
  • Veröffentlicht 16.07.2024 22:15:05
  • Zuletzt bearbeitet 21.11.2024 09:48:23

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App to retain access to the repository via a scoped user access token. This was only exploitable in public repositories while private ...

  • EPSS 0.27%
  • Veröffentlicht 16.07.2024 22:15:04
  • Zuletzt bearbeitet 21.11.2024 09:47:56

An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes defined on the related Personal Access Token. This vulnerability affected all versions of GitHub Enterprise Server prior to...

  • EPSS 0.12%
  • Veröffentlicht 20.06.2024 22:15:16
  • Zuletzt bearbeitet 27.08.2025 20:54:48

A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the Site Administrator role to gain arbitrary code execution capability on the GitHub Enterprise Server instance. Exploitation requir...

  • EPSS 0.4%
  • Veröffentlicht 20.05.2024 22:15:08
  • Zuletzt bearbeitet 27.08.2025 20:53:04

An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional encrypted assertions feature. This vulnerability allowed an attacker to forge a SAML respons...