Vulnerabilities > Github

DATE CVE VULNERABILITY TITLE RISK
2024-07-16 CVE-2024-5795 Resource Exhaustion vulnerability in Github Enterprise Server
A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause unbounded resource exhaustion by sending a large payload to the Git server.
network
low complexity
github CWE-400
6.5
2024-07-16 CVE-2024-5815 Cross-Site Request Forgery (CSRF) vulnerability in Github Enterprise Server
A Cross-Site Request Forgery vulnerability in GitHub Enterprise Server allowed write operations on a victim-owned repository by exploiting incorrect request types.
network
low complexity
github CWE-352
6.5
2024-07-16 CVE-2024-5816 Incorrect Authorization vulnerability in Github Enterprise Server
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App to retain access to the repository via a scoped user access token.
network
low complexity
github CWE-863
5.3
2024-07-16 CVE-2024-5817 Incorrect Authorization vulnerability in Github Enterprise Server
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed read access to issue content via GitHub Projects.
network
low complexity
github CWE-863
6.5
2024-07-16 CVE-2024-6336 Unspecified vulnerability in Github Enterprise Server
A Security Misconfiguration vulnerability in GitHub Enterprise Server allowed sensitive information disclosure to unauthorized users in GitHub Enterprise Server by exploiting organization ruleset feature.
network
low complexity
github
5.3
2024-07-16 CVE-2024-6395 Unspecified vulnerability in Github Enterprise Server
An exposure of sensitive information vulnerability in GitHub Enterprise Server would allow an attacker to enumerate the names of private repositories that utilize deploy keys.
network
low complexity
github
5.3
2024-02-22 CVE-2024-25129 XXE vulnerability in Github Codeql CLI
The CodeQL CLI repo holds binaries for the CodeQL command line interface (CLI).
local
low complexity
github CWE-611
5.5
2024-02-14 CVE-2024-1482 Incorrect Authorization vulnerability in Github Enterprise Server
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to create new branches in public repositories and run arbitrary GitHub Actions workflows with permissions from the GITHUB_TOKEN.
network
low complexity
github CWE-863
6.5
2024-02-13 CVE-2024-1082 Path Traversal vulnerability in Github Enterprise Server
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker to gain unauthorized read permission to files by deploying arbitrary symbolic links to a GitHub Pages site with a specially crafted artifact tarball.
network
low complexity
github CWE-22
6.5
2024-02-13 CVE-2024-1084 Cross-site Scripting vulnerability in Github Enterprise Server
Cross-site Scripting in the tag name pattern field in the tag protections UI in GitHub Enterprise Server allows a malicious website that requires user interaction and social engineering to make changes to a user account via CSP bypass with created CSRF tokens.
network
low complexity
github CWE-79
6.1