Vulnerabilities in GitHub

151 results
Vexday analysis

Com 119 CVEs catalogadas, o GitHub apresenta taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. Ainda assim, o cenário exige atenção: 13 vulnerabilidades são de severidade crítica e CVE-2024-0200 alcança EPSS de 0,7173 — valor que indica probabilidade elevada de exploração nos próximos 30 dias, tornando-a a principal prioridade de remediação no momento. O tipo de falha mais recorrente é CWE-863 (autorização incorreta), o que sugere fragilidades recorrentes no controle de acesso que merecem revisão estrutural. As 11 CVEs surgidas nos últimos 90 dias indicam cadência ativa de descoberta, reforçando a necessidade de monitoramento contínuo mesmo na ausência de exploração confirmada.

CVE-2023-22486LOWcmark-gfm Quadratic complexity bug in handle_close_bracket may lead to a denial of serviceEPSS 1.1%CVE-2021-22870Path traversal in GitHub Enterprise Server hosted Pages leads to unauthorized file read accessEPSS 1.1%CVE-2022-23741HIGHIncorrect authorization in GitHub Enterprise Server token generation leading to full admin accessEPSS 1.1%CVE-2024-3684HIGHImproper Privilege Management was identified in GitHub Enterprise Server that allowed privilege escalation in the Management ConsoleEPSS 1.1%CVE-2022-24722HIGHCross-site Scripting in view_componentEPSS 1.1%CVE-2023-22483LOWcmark-gfm Quadratic complexity bugs may lead to a denial of serviceEPSS 1.1%CVE-2020-10517Improper access control in GitHub Enterprise Server leading to the enumeration of private repository namesEPSS 1.1%CVE-2021-22866UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to user resourcesEPSS 1.0%CVE-2023-23760MEDIUMPath traversal in GitHub Enterprise Server leading to remote code executionEPSS 1.0%CVE-2023-26485MEDIUMQuadratic complexity may lead to a denial of service in cmark-gfmEPSS 1.0%CVE-2023-24824MEDIUMQuadratic complexity may lead to a denial of service in cmark-gfmEPSS 1.0%CVE-2022-31026MEDIUMUse of Uninitialized Variable in trilogyEPSS 1.0%CVE-2021-22863Improper access control in GitHub Enterprise Server leading to unauthorized changes to maintainer permissions on pull requestsEPSS 1.0%CVE-2023-22484LOWInefficient Quadratic complexity bug in handle_pointy_brace may lead to a denial of serviceEPSS 1.0%CVE-2021-22868Unsafe configuration options in GitHub Pages leading to path traversal on GitHub Enterprise ServerEPSS 0.9%CVE-2021-22861Improper access control in GitHub Enterprise Server leading to unauthorized write access to forkable repositoriesEPSS 0.9%CVE-2024-5746HIGHA Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the Site Administrator EPSS 0.9%CVE-2024-10007HIGHPre-Receive Hook Path Collision Vulnerability in GitHub Enterprise Server Allowing Privilege EscalationEPSS 0.8%CVE-2023-22381MEDIUMCode injection in GitHub Enterprise Server leading to arbitrary environment variables in GitHub ActionsEPSS 0.8%CVE-2023-6847HIGHImproper Authentication in GitHub Enterprise Server leading to Authentication Bypass for Public Repository DataEPSS 0.8%