GitHub enterprise server是美国GitHub公司的一款一座企业级代码托管服务器。 GitHub Enterprise Server存在授权问题漏洞,该漏洞源于授权缺失,未验证请求用户对规则库仓库的读取权限,可能导致已验证用户通过编码标识符枚举私有仓库元数据。以下版本受到影响:3.17.0版本至3.17.17版本、3.18.0版本至3.18.11版本、3.19.0版本至3.19.8版本、3.20.0版本至3.20.4版本和3.21.0版本至3.21.2版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GitHub | Enterprise Server | 3.17.0≤ 3.17.17 |
affected |
3.18.0≤ 3.18.11 |
affected | ||
3.19.0≤ 3.19.8 |
affected | ||
3.20.0≤ 3.20.4 |
affected | ||
3.21.0≤ 3.21.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GitHub | Enterprise Server | 3.17.0 ~ 3.17.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54163 | 4.7 MEDIUM | secure_headers: CSP directive injection via sandbox, plugin_types, and report_to when give |
| CVE-2026-15343 | Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrar | |
| CVE-2026-15007 | Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via |
No comments yet