Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

github — Vulnerabilities & Security Advisories 135

Browse all 135 CVE security advisories affecting github. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GitHub operates as a cloud-based platform for version control and collaborative software development, primarily hosting Git repositories for millions of developers worldwide. Its extensive attack surface has historically exposed it to critical vulnerability classes, including remote code execution, cross-site scripting, and privilege escalation, often stemming from complex integrations and third-party dependencies. With 131 recorded CVEs, the platform has faced significant security challenges, most notably the 2021 incident where attackers compromised two-factor authentication tokens to access internal systems, leading to the theft of source code from major clients. These breaches underscore the risks associated with centralized code hosting and the potential for supply chain attacks. While GitHub employs rigorous security measures, its scale and role as infrastructure for global software development make it a high-value target, necessitating continuous vigilance against both external exploits and insider threats to maintain the integrity of the open-source ecosystem.

Found 70 results / 135Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2023-46647 Improper Privilege Management in GitHub Enterprise Server management console leads to privilege escalation — Enterprise ServerCWE-269 8.0 High2023-12-21
CVE-2023-46646 GitHub Enterprise Server 安全漏洞 — Enterprise ServerCWE-639 5.3 Medium2023-12-21
CVE-2023-23766 Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling — Enterprise ServerCWE-697 4.5 Medium2023-09-22
CVE-2023-23763 Information disclosure in GitHub Enterprise Server leading to private repository leakage — Enterprise ServerCWE-200 5.3 Medium2023-09-01
CVE-2023-23765 Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling — Enterprise ServerCWE-697 4.8 Medium2023-08-30
CVE-2023-23764 Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling — Enterprise ServerCWE-697 4.8 Medium2023-07-27
CVE-2023-23762 Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling — Enterprise ServerCWE-697 6.5 Medium2023-04-07
CVE-2023-23761 Improper authentication vulnerability in GitHub Enterprise Server leading to modification of secret gists — Enterprise ServerCWE-287 7.7 High2023-04-07
CVE-2023-23760 Path traversal in GitHub Enterprise Server leading to remote code execution — Enterprise ServerCWE-22 4.9 Medium2023-03-08
CVE-2023-22381 Code injection in GitHub Enterprise Server leading to arbitrary environment variables in GitHub Actions — Enterprise ServerCWE-94 4.1 Medium2023-03-02

This page lists every published CVE security advisory associated with github. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.