Vulnerabilities > Github > Enterprise Server > 3.14.0

DATE CVE VULNERABILITY TITLE RISK
2024-09-23 CVE-2024-8263 Unspecified vulnerability in Github Enterprise Server
An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags.
network
low complexity
github
2.7
2024-09-23 CVE-2024-8770 Cross-site Scripting vulnerability in Github Enterprise Server
A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via social engineering. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.
network
low complexity
github CWE-79
6.1