Vulnerabilities > Github > Enterprise Server > 3.0.1

DATE CVE VULNERABILITY TITLE RISK
2022-12-14 CVE-2022-46256 Path Traversal vulnerability in Github Enterprise Server
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site.
network
low complexity
github CWE-22
8.8
2022-12-01 CVE-2022-23737 Improper Privilege Management vulnerability in Github Enterprise Server
An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privileges to create or delete pages via the API.
network
low complexity
github CWE-269
6.5
2022-10-19 CVE-2022-23734 Deserialization of Untrusted Data vulnerability in Github Enterprise Server
A deserialization of untrusted data vulnerability was identified in GitHub Enterprise Server that could potentially lead to remote code execution on the SVNBridge.
network
low complexity
github CWE-502
8.8
2022-04-05 CVE-2022-23732 Path Traversal vulnerability in Github Enterprise Server
A path traversal vulnerability was identified in GitHub Enterprise Server management console that allowed the bypass of CSRF protections.
network
low complexity
github CWE-22
8.8
2022-02-18 CVE-2021-41599 Unspecified vulnerability in Github Enterprise Server
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site.
network
low complexity
github
8.8
2022-01-25 CVE-2021-41598 Unspecified vulnerability in Github Enterprise Server
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's user-authorization web flow than was displayed to the user during approval.
network
low complexity
github
8.8
2021-11-10 CVE-2021-22870 Path Traversal vulnerability in Github Enterprise Server
A path traversal vulnerability was identified in GitHub Pages builds on GitHub Enterprise Server that could allow an attacker to read system files.
network
low complexity
github CWE-22
6.5
2021-09-24 CVE-2021-22868 Path Traversal vulnerability in Github Enterprise Server
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site.
network
low complexity
github CWE-22
4.3
2021-09-24 CVE-2021-22869 Improper Authentication vulnerability in Github Enterprise Server
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to.
network
low complexity
github CWE-287
critical
9.8
2021-07-14 CVE-2021-22867 Path Traversal vulnerability in Github Enterprise Server
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site.
network
low complexity
github CWE-22
6.5