Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Enterprise Server — Vulnerabilities & Security Advisories 83

All 83 CVE vulnerabilities found in Enterprise Server, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations associated with the Enterprise Server product offered by the vendor. It serves as a centralized repository for tracking security flaws within this specific enterprise-grade infrastructure component, focusing on the categorization and analysis of identified vulnerabilities rather than promoting features or benefits. The content aggregates data on various security weaknesses, including but not limited to injection flaws, broken access control, and security misconfigurations, covering reported incidents from the earliest known releases up to the present day. This comprehensive scope ensures that administrators and security professionals have access to historical context as well as recent developments in the security posture of the software. Readers can utilize this resource to track the vendor's security advisories over time, gaining insight into how quickly patches are deployed for critical issues. Additionally, the page allows users to understand the characteristics and prevalence of specific weakness classes within the Enterprise Server ecosystem, helping them prioritize remediation efforts based on risk severity. Users can also look up the product's vulnerability history to assess long-term stability and identify recurring patterns in code quality or configuration management. By providing a structured overview of known issues, this aggregation supports informed decision-making for system updates and compliance audits without requiring exhaustive manual research across multiple disparate sources.

Vendor: GitHub

CVE IDTitleCVSSSeverityPublished
CVE-2024-0200 Unsafe Reflection in Github Enterprise Server leading to Command Injection CWE-470 7.2 High2024-01-16
CVE-2023-6847 Improper Authentication in GitHub Enterprise Server leading to Authentication Bypass for Public Repository Data CWE-287 7.5 High2023-12-21
CVE-2023-51380 Incorrect Authorization allows Read Access to Issue Comments in GitHub Enterprise Server CWE-863 2.7 Low2023-12-21
CVE-2023-51379 Incorrect Authorization for Issue Comments in GitHub Enterprise Server CWE-863 4.9 Medium2023-12-21
CVE-2023-46648 Insufficient Entropy in GitHub Enterprise Server Management Console Invitation Token CWE-331 8.3 High2023-12-21
CVE-2023-46649 Race Condition allows Administrative Access on Organization Repositories CWE-367 6.3 Medium2023-12-21
CVE-2023-6804 Improper Privilege Management allows for arbitrary workflows to be run CWE-269 6.5 Medium2023-12-21
CVE-2023-6803 Race Condition allows Unauthorized Outside Collaborator CWE-367 5.8 Medium2023-12-21
CVE-2023-6802 Sensitive Information in Log File in GitHub Enterprise Server CWE-532 7.2 High2023-12-21
CVE-2023-6746 Sensitive Information in Log File in GitHub Enterprise Server CWE-532 8.1 High2023-12-21
CVE-2023-46645 Path traversal in GitHub Enterprise Server leading to arbitrary file reading when building a GitHub Pages site CWE-22 6.8 Medium2023-12-21
CVE-2023-6690 GitHub Enterprise Server 安全漏洞 CWE-367 3.9 Low2023-12-21
CVE-2023-46647 Improper Privilege Management in GitHub Enterprise Server management console leads to privilege escalation CWE-269 8.0 High2023-12-21
CVE-2023-46646 GitHub Enterprise Server 安全漏洞 CWE-639 5.3 Medium2023-12-21
CVE-2023-23766 Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling CWE-697 4.5 Medium2023-09-22
CVE-2023-23763 Information disclosure in GitHub Enterprise Server leading to private repository leakage CWE-200 5.3 Medium2023-09-01
CVE-2023-23765 Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling CWE-697 4.8 Medium2023-08-30
CVE-2023-23764 Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling CWE-697 4.8 Medium2023-07-27
CVE-2023-32265 Mitigations and availability of updates relating to security vulnerability in ESCWA component CVE-2023-32265. 7.1 High2023-07-20
CVE-2023-23762 Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling CWE-697 6.5 Medium2023-04-07
CVE-2023-23761 Improper authentication vulnerability in GitHub Enterprise Server leading to modification of secret gists CWE-287 7.7 High2023-04-07
CVE-2023-23760 Path traversal in GitHub Enterprise Server leading to remote code execution CWE-22 4.9 Medium2023-03-08
CVE-2023-22381 Code injection in GitHub Enterprise Server leading to arbitrary environment variables in GitHub Actions CWE-94 4.1 Medium2023-03-02

All 83 known CVE vulnerabilities affecting Enterprise Server with full Chinese analysis, references, and POCs where available.