Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Enterprise Server — Vulnerabilities & Security Advisories 89

All 89 CVE vulnerabilities found in Enterprise Server, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability disclosures for the vendor's Enterprise Server product, focusing on known software weaknesses and their associated risk tags. It collects a comprehensive history of security advisories and defect reports, covering incidents from the product's initial release through the present day. Readers can use this repository to track the vendor's advisory patterns, analyze specific weakness classes, and review the full vulnerability timeline of this product. The data is organized to support threat modeling and patch management, enabling users to identify recurring fault types and correlate them with specific update cycles. No individual CVE identifiers are listed in this summary; the focus remains on the structural relationship between the vendor, the product, and the nature of the defects. This resource is intended for security teams and infrastructure administrators who need a clear, chronological view of the product's security posture. It facilitates rapid assessment of which vulnerability classes have historically impacted the Enterprise Server and how the vendor responded to each report.

Vendor: GitHub

CVE ID Title CVSS Severity Published
CVE-2024-1359 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical 2024-02-13
CVE-2024-1355 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical 2024-02-13
CVE-2024-1354 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 8.0 High 2024-02-13
CVE-2024-1082 Path traversal vulnerability in GitHub Enterprise Server that allowed arbitrary file read with a specially crafted GitHub Pages artifact upload CWE-22 6.3 Medium 2024-02-13
CVE-2024-1084 GitHub Enterprise Server 安全漏洞 CWE-79 6.5 Medium 2024-02-13
CVE-2024-0507 Privilege Escalation by Code Injection in the Management Console in GitHub Enterprise Server CWE-20 6.5 Medium 2024-01-16
CVE-2024-0200 Unsafe Reflection in Github Enterprise Server leading to Command Injection CWE-470 7.2 High 2024-01-16
CVE-2023-6847 Improper Authentication in GitHub Enterprise Server leading to Authentication Bypass for Public Repository Data CWE-287 7.5 High 2023-12-21
CVE-2023-51380 Incorrect Authorization allows Read Access to Issue Comments in GitHub Enterprise Server CWE-863 2.7 Low 2023-12-21
CVE-2023-51379 Incorrect Authorization for Issue Comments in GitHub Enterprise Server CWE-863 4.9 Medium 2023-12-21
CVE-2023-46648 Insufficient Entropy in GitHub Enterprise Server Management Console Invitation Token CWE-331 8.3 High 2023-12-21
CVE-2023-46649 Race Condition allows Administrative Access on Organization Repositories CWE-367 6.3 Medium 2023-12-21
CVE-2023-6804 Improper Privilege Management allows for arbitrary workflows to be run CWE-269 6.5 Medium 2023-12-21
CVE-2023-6803 Race Condition allows Unauthorized Outside Collaborator CWE-367 5.8 Medium 2023-12-21
CVE-2023-6802 Sensitive Information in Log File in GitHub Enterprise Server CWE-532 7.2 High 2023-12-21
CVE-2023-6746 Sensitive Information in Log File in GitHub Enterprise Server CWE-532 8.1 High 2023-12-21
CVE-2023-46645 Path traversal in GitHub Enterprise Server leading to arbitrary file reading when building a GitHub Pages site CWE-22 6.8 Medium 2023-12-21
CVE-2023-6690 GitHub Enterprise Server 安全漏洞 CWE-367 3.9 Low 2023-12-21
CVE-2023-46647 Improper Privilege Management in GitHub Enterprise Server management console leads to privilege escalation CWE-269 8.0 High 2023-12-21
CVE-2023-46646 GitHub Enterprise Server 安全漏洞 CWE-639 5.3 Medium 2023-12-21
CVE-2023-23766 Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling CWE-697 4.5 Medium 2023-09-22
CVE-2023-23763 Information disclosure in GitHub Enterprise Server leading to private repository leakage CWE-200 5.3 Medium 2023-09-01
CVE-2023-23765 Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling CWE-697 4.8 Medium 2023-08-30
CVE-2023-23764 Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling CWE-697 4.8 Medium 2023-07-27
CVE-2023-32265 Mitigations and availability of updates relating to security vulnerability in ESCWA component CVE-2023-32265. 7.1 High 2023-07-20
CVE-2023-23762 Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling CWE-697 6.5 Medium 2023-04-07
CVE-2023-23761 Improper authentication vulnerability in GitHub Enterprise Server leading to modification of secret gists CWE-287 7.7 High 2023-04-07
CVE-2023-23760 Path traversal in GitHub Enterprise Server leading to remote code execution CWE-22 4.9 Medium 2023-03-08
CVE-2023-22381 Code injection in GitHub Enterprise Server leading to arbitrary environment variables in GitHub Actions CWE-94 4.1 Medium 2023-03-02

All 89 known CVE vulnerabilities affecting Enterprise Server with full Chinese analysis, references, and POCs where available.