Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Enterprise Server — Vulnerabilities & Security Advisories 74

All 74 CVE vulnerabilities found in Enterprise Server, with AI-generated Chinese analysis, references, and POCs.

This page details Common Vulnerabilities and Exposures (CVE) weaknesses associated with Enterprise Server. It aggregates known security flaws, misconfigurations, and software bugs affecting the Enterprise Server product line, spanning from early 2020 to the present. Users can leverage this resource to track vendor advisories for the platform, understand the characteristics and impact of specific weakness classes, and look up the product's vulnerability history to assess risk over time. The data is curated to provide a comprehensive view of the security posture of Enterprise Server, highlighting critical issues that may impact enterprise operations. By consolidating information from various sources, this aggregation enables security professionals, system administrators, and compliance officers to maintain an accurate and up-to-date inventory of known vulnerabilities. The page emphasizes clarity and accessibility, ensuring that relevant technical details are available without unnecessary complexity. This approach supports informed decision-making regarding patch management, risk mitigation, and security monitoring. The content is regularly updated to reflect the latest findings and vendor disclosures. It serves as a central reference point for understanding the threat landscape surrounding Enterprise Server, helping organizations prioritize remediation efforts based on severity and exposure. This resource is intended for technical audiences who require precise and actionable security intelligence.

Vendor: GitHub

CVE IDTitleCVSSSeverityPublished
CVE-2024-10007 Pre-Receive Hook Path Collision Vulnerability in GitHub Enterprise Server Allowing Privilege Escalation CWE-59 9.1AICriticalAI2024-11-07
CVE-2024-9487 An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed when the encrypted assertions feature was enabled CWE-347 9.8AICriticalAI2024-10-10
CVE-2024-4985 GitHub Enterprise Server 安全漏洞 CWE-303 9.8AICriticalAI2024-05-20
CVE-2024-2440 Race Condition was identified in GitHub Enterprise Server that allowed maintaining admin permissions CWE-367 5.5 Medium2024-04-19
CVE-2024-3684 Improper Privilege Management was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console CWE-88 8.0 High2024-04-19
CVE-2024-3646 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console CWE-20 8.0 High2024-04-19
CVE-2024-3470 Repository administrator can bypass organization's ruleset using deploy keys CWE-269 5.9 Medium2024-04-19
CVE-2024-2748 CSRF vulnerability was identified in GitHub Enterprise Server that allowed performing actions on behalf of a user CWE-352 4.3 Medium2024-03-20
CVE-2024-2469 Remote Code Execution in GitHub Enterprise Server Allowed Administrators to gain SSH access to the appliance CWE-20 8.0 High2024-03-20
CVE-2024-1908 Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed Privilege Escalation CWE-269 6.3 Medium2024-02-29
CVE-2024-1482 Improper Authorization in GitHub Enterprise Server allowed unauthorized workflow execution CWE-863 7.1 High2024-02-14
CVE-2024-1378 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical2024-02-13
CVE-2024-1374 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical2024-02-13
CVE-2024-1372 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical2024-02-13
CVE-2024-1369 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical2024-02-13
CVE-2024-1359 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical2024-02-13
CVE-2024-1355 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical2024-02-13
CVE-2024-1354 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 8.0 High2024-02-13
CVE-2024-1082 Path traversal vulnerability in GitHub Enterprise Server that allowed arbitrary file read with a specially crafted GitHub Pages artifact upload CWE-22 6.3 Medium2024-02-13
CVE-2024-1084 GitHub Enterprise Server 安全漏洞 CWE-79 6.5 Medium2024-02-13
CVE-2024-0507 Privilege Escalation by Code Injection in the Management Console in GitHub Enterprise Server CWE-20 6.5 Medium2024-01-16
CVE-2024-0200 Unsafe Reflection in Github Enterprise Server leading to Command Injection CWE-470 7.2 High2024-01-16
CVE-2023-6847 Improper Authentication in GitHub Enterprise Server leading to Authentication Bypass for Public Repository Data CWE-287 7.5 High2023-12-21
CVE-2023-51380 Incorrect Authorization allows Read Access to Issue Comments in GitHub Enterprise Server CWE-863 2.7 Low2023-12-21
CVE-2023-51379 Incorrect Authorization for Issue Comments in GitHub Enterprise Server CWE-863 4.9 Medium2023-12-21
CVE-2023-46648 Insufficient Entropy in GitHub Enterprise Server Management Console Invitation Token CWE-331 8.3 High2023-12-21
CVE-2023-46649 Race Condition allows Administrative Access on Organization Repositories CWE-367 6.3 Medium2023-12-21
CVE-2023-6804 Improper Privilege Management allows for arbitrary workflows to be run CWE-269 6.5 Medium2023-12-21
CVE-2023-6803 Race Condition allows Unauthorized Outside Collaborator CWE-367 5.8 Medium2023-12-21
CVE-2023-6802 Sensitive Information in Log File in GitHub Enterprise Server CWE-532 7.2 High2023-12-21

All 74 known CVE vulnerabilities affecting Enterprise Server with full Chinese analysis, references, and POCs where available.