Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Enterprise Server — Vulnerabilities & Security Advisories 75

All 75 CVE vulnerabilities found in Enterprise Server, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the Enterprise Server product, focusing on identified weakness types and associated security tags. It collects comprehensive data on known vulnerabilities, including remote code execution, privilege escalation, and cross-site scripting flaws, covering security issues reported and patched between 2015 and 2024. By utilizing this centralized repository, users can effectively track a vendor’s historical advisories to understand the pace and nature of security updates over time. Additionally, you can gain deeper insights into specific weakness classes to assess their prevalence and impact within the Enterprise Server ecosystem. The interface also allows you to look up a product’s vulnerability history, providing a clear timeline of how security risks have evolved and been mitigated in response to emerging threats. This data-driven approach supports risk management teams in prioritizing patches and understanding the security posture of their infrastructure. All entries are categorized by severity and affected versions, enabling precise filtering for targeted analysis. The goal is to provide transparent, accessible information that aids in compliance reporting and proactive defense strategies without overwhelming the user with unnecessary technical noise. This resource serves as a foundational reference for security analysts, IT administrators, and compliance officers seeking to maintain the integrity and resilience of their enterprise environments against known cyber threats.

Vendor: GitHub

CVE IDTitleCVSSSeverityPublished
CVE-2024-10824 Authorization Bypass Vulnerability was Identified in GitHub Enterprise Server that Allowed Unauthorized Internal Users to Access Secret Scanning Alert Data CWE-862 4.3AIMediumAI2024-11-07
CVE-2024-10007 Pre-Receive Hook Path Collision Vulnerability in GitHub Enterprise Server Allowing Privilege Escalation CWE-59 9.1AICriticalAI2024-11-07
CVE-2024-9487 An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed when the encrypted assertions feature was enabled CWE-347 9.8AICriticalAI2024-10-10
CVE-2024-4985 GitHub Enterprise Server 安全漏洞 CWE-303 9.8AICriticalAI2024-05-20
CVE-2024-2440 Race Condition was identified in GitHub Enterprise Server that allowed maintaining admin permissions CWE-367 5.5 Medium2024-04-19
CVE-2024-3684 Improper Privilege Management was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console CWE-88 8.0 High2024-04-19
CVE-2024-3646 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console CWE-20 8.0 High2024-04-19
CVE-2024-3470 Repository administrator can bypass organization's ruleset using deploy keys CWE-269 5.9 Medium2024-04-19
CVE-2024-2748 CSRF vulnerability was identified in GitHub Enterprise Server that allowed performing actions on behalf of a user CWE-352 4.3 Medium2024-03-20
CVE-2024-2469 Remote Code Execution in GitHub Enterprise Server Allowed Administrators to gain SSH access to the appliance CWE-20 8.0 High2024-03-20
CVE-2024-1908 Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed Privilege Escalation CWE-269 6.3 Medium2024-02-29
CVE-2024-1482 Improper Authorization in GitHub Enterprise Server allowed unauthorized workflow execution CWE-863 7.1 High2024-02-14
CVE-2024-1378 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical2024-02-13
CVE-2024-1374 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical2024-02-13
CVE-2024-1372 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical2024-02-13
CVE-2024-1369 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical2024-02-13
CVE-2024-1359 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical2024-02-13
CVE-2024-1355 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 9.1 Critical2024-02-13
CVE-2024-1354 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console CWE-20 8.0 High2024-02-13
CVE-2024-1082 Path traversal vulnerability in GitHub Enterprise Server that allowed arbitrary file read with a specially crafted GitHub Pages artifact upload CWE-22 6.3 Medium2024-02-13
CVE-2024-1084 GitHub Enterprise Server 安全漏洞 CWE-79 6.5 Medium2024-02-13
CVE-2024-0507 Privilege Escalation by Code Injection in the Management Console in GitHub Enterprise Server CWE-20 6.5 Medium2024-01-16
CVE-2024-0200 Unsafe Reflection in Github Enterprise Server leading to Command Injection CWE-470 7.2 High2024-01-16
CVE-2023-6847 Improper Authentication in GitHub Enterprise Server leading to Authentication Bypass for Public Repository Data CWE-287 7.5 High2023-12-21
CVE-2023-51380 Incorrect Authorization allows Read Access to Issue Comments in GitHub Enterprise Server CWE-863 2.7 Low2023-12-21
CVE-2023-51379 Incorrect Authorization for Issue Comments in GitHub Enterprise Server CWE-863 4.9 Medium2023-12-21
CVE-2023-46648 Insufficient Entropy in GitHub Enterprise Server Management Console Invitation Token CWE-331 8.3 High2023-12-21
CVE-2023-46649 Race Condition allows Administrative Access on Organization Repositories CWE-367 6.3 Medium2023-12-21
CVE-2023-6804 Improper Privilege Management allows for arbitrary workflows to be run CWE-269 6.5 Medium2023-12-21
CVE-2023-6803 Race Condition allows Unauthorized Outside Collaborator CWE-367 5.8 Medium2023-12-21

All 75 known CVE vulnerabilities affecting Enterprise Server with full Chinese analysis, references, and POCs where available.