Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Enterprise Server — Vulnerabilities & Security Advisories 83

All 83 CVE vulnerabilities found in Enterprise Server, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations associated with the Enterprise Server product offered by the vendor. It serves as a centralized repository for tracking security flaws within this specific enterprise-grade infrastructure component, focusing on the categorization and analysis of identified vulnerabilities rather than promoting features or benefits. The content aggregates data on various security weaknesses, including but not limited to injection flaws, broken access control, and security misconfigurations, covering reported incidents from the earliest known releases up to the present day. This comprehensive scope ensures that administrators and security professionals have access to historical context as well as recent developments in the security posture of the software. Readers can utilize this resource to track the vendor's security advisories over time, gaining insight into how quickly patches are deployed for critical issues. Additionally, the page allows users to understand the characteristics and prevalence of specific weakness classes within the Enterprise Server ecosystem, helping them prioritize remediation efforts based on risk severity. Users can also look up the product's vulnerability history to assess long-term stability and identify recurring patterns in code quality or configuration management. By providing a structured overview of known issues, this aggregation supports informed decision-making for system updates and compliance audits without requiring exhaustive manual research across multiple disparate sources.

Vendor: GitHub

CVE ID Title CVSS Severity Published
CVE-2025-11892 DOM-based Cross-Site Scripting was identified in GitHub Enterprise Server Issues search allows privilege escalation and unauthorized workflow triggers CWE-79 6.1 - 2025-11-10
CVE-2025-8447 Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed read-only access CWE-639 3.1AI Low AI 2025-08-26
CVE-2025-6981 Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized read-only access CWE-863 7.5AI High AI 2025-07-15
CVE-2025-3509 Pre-Receive Hook Remote Code Execution vulnerability was identified in GitHub Enterprise Server that allowing Privilege Escalation CWE-94 6.6AI Medium AI 2025-04-17
CVE-2025-3124 Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized access to private repository names CWE-862 4.3AI Medium AI 2025-04-17
CVE-2024-10001 Code Injection Vulnerability in GitHub Enterprise Server Allows Arbitrary Code Execution via Message Handling CWE-94 8.3 - 2025-01-29
CVE-2025-23369 Improper Verification of Cryptographic Signature in GitHub Enterprise Server Allows Signature Spoofing by Improper Validation CWE-347 7.5 - 2025-01-21
CVE-2024-8810 Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed GitHub Apps to grant themselves write access CWE-269 6.5AI Medium AI 2024-11-07
CVE-2024-10824 Authorization Bypass Vulnerability was Identified in GitHub Enterprise Server that Allowed Unauthorized Internal Users to Access Secret Scanning Alert Data CWE-862 4.3AI Medium AI 2024-11-07
CVE-2024-10007 Pre-Receive Hook Path Collision Vulnerability in GitHub Enterprise Server Allowing Privilege Escalation CWE-59 9.1AI Critical AI 2024-11-07
CVE-2024-9487 An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed when the encrypted assertions feature was enabled CWE-347 9.8AI Critical AI 2024-10-10
CVE-2024-4985 GitHub Enterprise Server 安全漏洞 CWE-303 9.8AI Critical AI 2024-05-20
CVE-2024-2440 Race Condition was identified in GitHub Enterprise Server that allowed maintaining admin permissions CWE-367 5.5 Medium 2024-04-19
CVE-2024-3684 Improper Privilege Management was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console CWE-88 8.0 High 2024-04-19
CVE-2024-3646 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console CWE-20 8.0 High 2024-04-19
CVE-2024-3470 Repository administrator can bypass organization's ruleset using deploy keys CWE-269 5.9 Medium 2024-04-19
CVE-2024-2748 CSRF vulnerability was identified in GitHub Enterprise Server that allowed performing actions on behalf of a user CWE-352 4.3 Medium 2024-03-20
CVE-2024-2469 Remote Code Execution in GitHub Enterprise Server Allowed Administrators to gain SSH access to the appliance CWE-20 8.0 High 2024-03-20
CVE-2024-1908 Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed Privilege Escalation CWE-269 6.3 Medium 2024-02-29
CVE-2024-1482 Improper Authorization in GitHub Enterprise Server allowed unauthorized workflow execution CWE-863 7.1 High 2024-02-14
CVE-2024-1378 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical 2024-02-13
CVE-2024-1374 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical 2024-02-13
CVE-2024-1372 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical 2024-02-13
CVE-2024-1369 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical 2024-02-13
CVE-2024-1359 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical 2024-02-13
CVE-2024-1355 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical 2024-02-13
CVE-2024-1354 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 8.0 High 2024-02-13
CVE-2024-1082 Path traversal vulnerability in GitHub Enterprise Server that allowed arbitrary file read with a specially crafted GitHub Pages artifact upload CWE-22 6.3 Medium 2024-02-13
CVE-2024-1084 GitHub Enterprise Server 安全漏洞 CWE-79 6.5 Medium 2024-02-13
CVE-2024-0507 Privilege Escalation by Code Injection in the Management Console in GitHub Enterprise Server CWE-20 6.5 Medium 2024-01-16

All 83 known CVE vulnerabilities affecting Enterprise Server with full Chinese analysis, references, and POCs where available.