Vulnerabilities > Github > Enterprise Server > 3.11.2

DATE CVE VULNERABILITY TITLE RISK
2024-02-13 CVE-2024-1369 Command Injection vulnerability in Github Enterprise Server
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when setting the username and password for collectd configurations.
network
low complexity
github CWE-77
critical
9.1
2024-02-13 CVE-2024-1372 Command Injection vulnerability in Github Enterprise Server
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when configuring SAML settings.
network
low complexity
github CWE-77
critical
9.1
2024-02-13 CVE-2024-1374 Command Injection vulnerability in Github Enterprise Server
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring audit log forwarding.
network
low complexity
github CWE-77
critical
9.1
2024-02-13 CVE-2024-1378 Command Injection vulnerability in Github Enterprise Server
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring SMTP options.
network
low complexity
github CWE-77
critical
9.1
2024-01-16 CVE-2024-0200 Unsafe Reflection vulnerability in Github Enterprise Server
An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection.
network
low complexity
github CWE-470
critical
9.8
2024-01-16 CVE-2024-0507 Command Injection vulnerability in Github Enterprise Server
An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console.
network
low complexity
github CWE-77
8.8