Vulnerabilities > Github > Enterprise Server > 2.8.17

DATE CVE VULNERABILITY TITLE RISK
2022-12-14 CVE-2022-46256 Path Traversal vulnerability in Github Enterprise Server
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site.
network
low complexity
github CWE-22
8.8
2022-12-01 CVE-2022-23737 Improper Privilege Management vulnerability in Github Enterprise Server
An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privileges to create or delete pages via the API.
network
low complexity
github CWE-269
6.5
2022-10-19 CVE-2022-23734 Deserialization of Untrusted Data vulnerability in Github Enterprise Server
A deserialization of untrusted data vulnerability was identified in GitHub Enterprise Server that could potentially lead to remote code execution on the SVNBridge.
network
low complexity
github CWE-502
8.8
2022-04-05 CVE-2022-23732 Path Traversal vulnerability in Github Enterprise Server
A path traversal vulnerability was identified in GitHub Enterprise Server management console that allowed the bypass of CSRF protections.
network
low complexity
github CWE-22
8.8
2022-01-25 CVE-2021-41598 Unspecified vulnerability in Github Enterprise Server
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's user-authorization web flow than was displayed to the user during approval.
network
low complexity
github
8.8
2021-11-10 CVE-2021-22870 Path Traversal vulnerability in Github Enterprise Server
A path traversal vulnerability was identified in GitHub Pages builds on GitHub Enterprise Server that could allow an attacker to read system files.
network
low complexity
github CWE-22
6.5
2021-09-24 CVE-2021-22868 Path Traversal vulnerability in Github Enterprise Server
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site.
network
low complexity
github CWE-22
4.3
2021-07-14 CVE-2021-22867 Path Traversal vulnerability in Github Enterprise Server
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site.
network
low complexity
github CWE-22
6.5
2021-04-02 CVE-2021-22865 Unspecified vulnerability in Github Enterprise Server
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed access tokens generated from a GitHub App's web authentication flow to read private repository metadata via the REST API without having been granted the appropriate permissions.
network
low complexity
github
6.5