Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

GitHub Enterprise Server — Vulnerabilities & Security Advisories 46

All 46 CVE vulnerabilities found in GitHub Enterprise Server, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities for GitHub Enterprise Server, categorized by Common Weakness Enumeration types and specific security tags. It collects a comprehensive list of security flaws ranging from critical remote code execution risks to lower-severity information disclosure issues, covering all published advisory data with no arbitrary time restrictions. Visitors can use this resource to track vendor-specific advisories as they are released, gain a deeper understanding of prevalent weakness classes affecting the platform, and investigate the historical vulnerability profile of the software to assess long-term security posture. The content is organized to facilitate easy navigation by severity, component, or vulnerability identifier, allowing security teams to quickly identify relevant patches or workarounds. By consolidating these records in one location, the page serves as a central reference point for administrators responsible for maintaining the integrity and compliance of their GitHub Enterprise environments. Users can cross-reference weakness types with official vendor guidance to prioritize remediation efforts effectively. This structured approach ensures that stakeholders have immediate access to critical information needed to mitigate risks, verify patch status, and maintain secure operations across their deployment infrastructure without relying on fragmented sources.

Vendor: GitHub

CVE IDTitleCVSSSeverityPublished
CVE-2025-6600 GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Search API CWE-200 5.3AIMediumAI2025-07-01
CVE-2025-3246 Markdown math block sanitization bypass allows privilege escalation and unauthorized workflow triggers CWE-79 5.4AIMediumAI2025-04-17
CVE-2024-9539 GitHub Enterprise Server 安全漏洞 CWE-200 4.3AIMediumAI2024-10-11
CVE-2024-8263 GitHub Enterprise Server 安全漏洞 CWE-269 9.1AICriticalAI2024-09-23
CVE-2024-8770 GitHub Enterprise Server 安全漏洞 CWE-79 6.1AIMediumAI2024-09-23
CVE-2024-6800 GitHub Enterprise Server 安全漏洞 CWE-347 9.8AICriticalAI2024-08-20
CVE-2024-6337 Incorrect Authorization allows read access to issues in GitHub Enterprise Server CWE-863 4.3AIMediumAI2024-08-20
CVE-2024-7711 GitHub Enterprise Server 安全漏洞 CWE-863 5.3AIMediumAI2024-08-20
CVE-2024-6395 GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Deploy Keys CWE-200 5.3AIMediumAI2024-07-16
CVE-2024-6336 Security misconfiguration was identified in GitHub Enterprise Server that allowed sensitive data exposure CWE-200 4.3AIMediumAI2024-07-16
CVE-2024-5817 Improper authorization allows read access to issue content in GitHub Enterprise Server CWE-863 4.3AIMediumAI2024-07-16
CVE-2024-5816 Improper authorization allows persistent access in GitHub Enterprise Server CWE-863 9.4AICriticalAI2024-07-16
CVE-2024-5815 Cross Site Request Forgery was identified in GitHub Enterprise Server that allowed write in a user owned repository CWE-352 5.7AIMediumAI2024-07-16
CVE-2024-5795 Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed resource exhaustion CWE-400 7.7 High2024-07-16
CVE-2024-5566 Improper Privilege Management allows for access to unauthorized repository content during migration CWE-269 5.8 Medium2024-07-16
CVE-2024-5746 GitHub Enterprise Server 安全漏洞 CWE-918 7.6 High2024-06-20
CVE-2024-2443 Improper input validation vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console CWE-20 9.1 Critical2024-03-20
CVE-2022-46257 Information disclosure in GitHub Enterprise Server leading to unauthorized viewing of private repository names CWE-200 6.5 -2023-03-07
CVE-2023-22380 Path traversal in GitHub Enterprise Server leading to arbitrary file reading when building a GitHub Pages site CWE-22 6.5 -2023-02-16
CVE-2022-23739 Incorrect authorization check in GitHub Enterprise Server leading to escalation of privileges in GraphQL API requests from GitHub Apps using scoped user-to-server tokens CWE-863 7.8 -2023-01-17
CVE-2022-46258 Incorrect Authorization in GitHub Enterprise Server leads to Action Workflow modifications without Workflow Scope CWE-863 6.5 -2023-01-09
CVE-2022-23741 Incorrect authorization in GitHub Enterprise Server token generation leading to full admin access CWE-863 7.2 -2022-12-14
CVE-2022-46256 Path traversal in GitHub Enterprise Server leading to remote code execution in GitHub Pages CWE-22 8.8 -2022-12-14
CVE-2022-46255 Improper Limitation of a Pathname to a Restricted Directory in GitHub Enterprise Server leading to RCE CWE-22 9.8 -2022-12-14
CVE-2022-23737 Improper Privilege Management in GitHub Enterprise Server leading to page creation and deletion CWE-269 6.5 -2022-12-01
CVE-2022-23740 Improper Neutralization of Argument Delimiters in a Command in GitHub Enterprise Server leading to Remote Code Execution CWE-88 8.8 -2022-11-23
CVE-2022-23738 Incomplete cache verification issue in GitHub Enterprise Server leading to exposure of private repo files CWE-200 5.7 -2022-11-01
CVE-2022-23734 Deserialization of Untrusted Data vulnerability in GitHub Enterprise Server leading to Remote Code Execution CWE-502 8.8 -2022-10-19
CVE-2022-23733 Stored XSS vulnerability in GitHub Enterprise Server leading to injection of arbitrary attributes CWE-79 5.4 -2022-08-02
CVE-2022-23732 Path traversal in GitHub Enterprise Server management console leading to a bypass of CSRF protections CWE-23 8.8 -2022-04-05

All 46 known CVE vulnerabilities affecting GitHub Enterprise Server with full Chinese analysis, references, and POCs where available.