Vulnerabilities in GitHub

151 results
Vexday analysis

Com 119 CVEs catalogadas, o GitHub apresenta taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. Ainda assim, o cenário exige atenção: 13 vulnerabilidades são de severidade crítica e CVE-2024-0200 alcança EPSS de 0,7173 — valor que indica probabilidade elevada de exploração nos próximos 30 dias, tornando-a a principal prioridade de remediação no momento. O tipo de falha mais recorrente é CWE-863 (autorização incorreta), o que sugere fragilidades recorrentes no controle de acesso que merecem revisão estrutural. As 11 CVEs surgidas nos últimos 90 dias indicam cadência ativa de descoberta, reforçando a necessidade de monitoramento contínuo mesmo na ausência de exploração confirmada.

CVE-2023-23766MEDIUMIncorrect comparison vulnerability in GitHub Enterprise Server leading to commit smugglingEPSS 0.6%CVE-2023-23764MEDIUMIncorrect comparison vulnerability in GitHub Enterprise Server leading to commit smugglingEPSS 0.6%CVE-2024-3470MEDIUMRepository administrator can bypass organization's ruleset using deploy keysEPSS 0.6%CVE-2022-23733Stored XSS vulnerability in GitHub Enterprise Server leading to injection of arbitrary attributesEPSS 0.6%CVE-2022-46257Information disclosure in GitHub Enterprise Server leading to unauthorized viewing of private repository namesEPSS 0.6%CVE-2022-46258MEDIUMIncorrect Authorization in GitHub Enterprise Server leads to Action Workflow modifications without Workflow ScopeEPSS 0.6%CVE-2024-5795HIGHDenial of Service vulnerability was identified in GitHub Enterprise Server that allowed resource exhaustionEPSS 0.6%CVE-2023-23763MEDIUMInformation disclosure in GitHub Enterprise Server leading to private repository leakageEPSS 0.5%CVE-2023-46646MEDIUMImproper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get EPSS 0.5%CVE-2024-5817MEDIUMImproper authorization allows read access to issue content in GitHub Enterprise ServerEPSS 0.5%CVE-2023-6746HIGHSensitive Information in Log File in GitHub Enterprise Server EPSS 0.5%CVE-2024-5816MEDIUMImproper authorization allows persistent access in GitHub Enterprise ServerEPSS 0.5%CVE-2024-7711MEDIUMAn Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, anEPSS 0.5%CVE-2024-6395MEDIUMGitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Deploy KeysEPSS 0.5%CVE-2023-23765MEDIUMIncorrect comparison vulnerability in GitHub Enterprise Server leading to commit smugglingEPSS 0.5%CVE-2024-5566MEDIUMImproper Privilege Management allows for access to unauthorized repository content during migrationEPSS 0.5%CVE-2024-1084MEDIUMCross-site Scripting in the tag name pattern field in the tag protections UI in GitHub Enterprise Server allows a malicious website that reqEPSS 0.5%CVE-2023-51380LOWIncorrect Authorization allows Read Access to Issue Comments in GitHub Enterprise ServerEPSS 0.5%CVE-2026-17556HIGHPath traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id headerEPSS 0.5%CVE-2023-23761HIGHImproper authentication vulnerability in GitHub Enterprise Server leading to modification of secret gistsEPSS 0.5%