Vulnerability index

Browse CVEs

131 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Server HIGH 7.1
CVE-2024-10001

A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious code into the query selector via…

Fix: 3.11.6 / 3.12.10+
Fix from $1,950 2025-01-29
Enterprise Server HIGH 8.8
CVE-2025-23369

An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed signature spoofing for unau…

Fix: 3.12.14 / 3.13.10+
Fix from $1,950 2025-01-21
Cli CRITICAL 9.6
CVE-2024-52308

The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ss…

Fix: 2.62.0+
Fix from $2,300 2024-11-14
Enterprise Server MEDIUM 6.5
CVE-2024-8810

A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from an organization administrator.…

Fix: 3.10.17 / 3.11.15+
Fix from $1,600 2024-11-07
Enterprise Server MEDIUM 6.5
CVE-2024-10824

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauthorized internal users to access sensitive secret …

Fix: 3.13.2+
Fix from $1,600 2024-11-07
Enterprise Server CRITICAL 9.1
CVE-2024-10007

A path collision and arbitrary code execution vulnerability was identified in GitHub Enterprise Server that allowed container escape to escalate to r…

Fix: 3.11.17 / 3.12.11+
Fix from $2,300 2024-11-07
Enterprise Server CRITICAL 9.1
CVE-2024-9487EPSS 25%

An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to …

Fix: 3.11.16 / 3.12.10+
Fix from $2,300 2024-10-10
Enterprise Server MEDIUM 6.1
CVE-2024-8770

A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to s…

Fix: 3.10.17 / 3.11.15+
Fix from $1,600 2024-09-23
Actions\/artifact HIGH 7.5
CVE-2024-42471

actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable t…

Fix: 2.1.7+
Fix from $1,950 2024-09-02
Enterprise Server CRITICAL 9.8
CVE-2024-6800

An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity provider…

Fix: 3.10.16 / 3.11.14+
Fix from $2,300 2024-08-20
Enterprise Server MEDIUM 6.5
CVE-2024-6337

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only content: read and pull_reques…

Fix: 3.10.16 / 3.11.14+
Fix from $1,600 2024-08-20
Enterprise Server MEDIUM 5.3
CVE-2024-6395

An exposure of sensitive information vulnerability in GitHub Enterprise Server would allow an attacker to enumerate the names of private repositories…

Fix: 3.9.17 / 3.10.14+
Fix from $1,600 2024-07-16
Enterprise Server MEDIUM 6.5
CVE-2024-5795

A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause unbounded resource exhaustion by sendi…

Fix: 3.9.17 / 3.10.14+
Fix from $1,600 2024-07-16
Enterprise Server MEDIUM 6.5
CVE-2024-5815

A Cross-Site Request Forgery vulnerability in GitHub Enterprise Server allowed write operations on a victim-owned repository by exploiting incorrect …

Fix: 3.9.17 / 3.10.14+
Fix from $1,600 2024-07-16
Enterprise Server MEDIUM 6.5
CVE-2024-5817

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed read access to issue content via GitHub Projects. Th…

Fix: 3.9.17 / 3.10.14+
Fix from $1,600 2024-07-16
Enterprise Server MEDIUM 5.3
CVE-2024-5816

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App to retain access to the repos…

Fix: 3.9.17 / 3.10.14+
Fix from $1,600 2024-07-16
Enterprise Server MEDIUM 5.3
CVE-2024-6336

A Security Misconfiguration vulnerability in GitHub Enterprise Server allowed sensitive information disclosure to unauthorized users in GitHub Enterp…

Fix: 3.9.17 / 3.10.14+
Fix from $1,600 2024-07-16
Enterprise Server MEDIUM 6.5
CVE-2024-5566

An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes defined on the related…

Fix: 3.9.17 / 3.10.14+
Fix from $1,600 2024-07-16
Enterprise Server HIGH 7.2
CVE-2024-5746

A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the Site Administrator role to g…

Fix: 3.9.16 / 3.10.13+
Fix from $1,950 2024-06-20
Enterprise Server CRITICAL 9.8
CVE-2024-4985

An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the …

Fix: 3.9.15 / 3.10.12+
Fix from $2,300 2024-05-20
Enterprise Server MEDIUM 5.9
CVE-2024-2440

A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on a detached repository by making a GraphQL mutation …

Fix: 3.9.13 / 3.10.10+
Fix from $1,600 2024-04-19
Enterprise Server HIGH 7.2
CVE-2024-3470

An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use a deploy key pertaining to …

Fix: 3.11.8 / 3.12.2+
Fix from $1,950 2024-04-19
Enterprise Server HIGH 7.2
CVE-2024-3646

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.9.13 / 3.10.10+
Fix from $1,950 2024-04-19
Enterprise Server HIGH 7.2
CVE-2024-3684

A server side request forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management…

Fix: 3.9.13 / 3.10.10+
Fix from $1,950 2024-04-19
Enterprise Server MEDIUM 6.5
CVE-2024-1908

An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use the Enterprise Actions GitH…

Fix: 3.8.16 / 3.9.11+
Fix from $1,600 2024-03-21
Enterprise Server HIGH 7.2
CVE-2024-2443

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.17 / 3.9.12+
Fix from $1,950 2024-03-20
Enterprise Server HIGH 7.2
CVE-2024-2469

An attacker with an Administrator role in GitHub Enterprise Server could gain SSH root access via remote code execution. This vulnerability affected …

Fix: 3.8.17 / 3.9.12+
Fix from $1,950 2024-03-20
Codeql Cli MEDIUM 5.5
CVE-2024-25129

The CodeQL CLI repo holds binaries for the CodeQL command line interface (CLI). Prior to version 2.16.3, an XML parser used by the CodeQL CLI to read…

Fix: 2.16.3+
Fix from $1,600 2024-02-22
Enterprise Server MEDIUM 6.5
CVE-2024-1482

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to create new branches in public reposit…

Fix: 3.9.10 / 3.10.7+
Fix from $1,600 2024-02-14
Enterprise Server CRITICAL 9.1
CVE-2024-1369

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $2,300 2024-02-13