GitHub enterprise server是美国GitHub公司的一款一座企业级代码托管服务器。 GitHub Enterprise Server存在跨站脚本漏洞,该漏洞源于AnsweredQuestionStructuredDataComponent未转义Q&A类别讨论标题,在嵌入到<script type="application/ld+json">块前导致标题可打破脚本环境,利用REST API的JSONP回调支持绕过内容安全策略,导致存储型跨站脚本攻击,允许经过身份验证的攻击者在另一用户浏览
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GitHub | Enterprise Server | 3.17.0≤ 3.17.16 |
affected |
3.18.0≤ 3.18.10 |
affected | ||
3.19.0≤ 3.19.7 |
affected | ||
3.20.0≤ 3.20.3 |
affected | ||
3.16.0≤ 3.16.19 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GitHub | Enterprise Server | 3.17.0 ~ 3.17.16 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9106 | UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organi | |
| CVE-2026-9132 | Missing authorization vulnerability in GitHub Enterprise Server allowed disclosure of priv |
No comments yet