Записи github
158 опубликованных записей вендора github.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 0,6 %
- Pre-auth RCE
- 9
- С записью об исправлении
- 81,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-863 Incorrect Authorization14
- CWE-20 Improper Input Validation13
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor9
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')9
- CWE-269 Improper Privilege Management8
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
158 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
61На этой неделе | CVE-2024-0200Proof of concept | Unsafe Reflection in Github Enterprise Server leading to Command Injectiongithub · enterprise server · CWE-470 | Критическая9,8 | — | 71,7 % | 16 янв. 2024 г. |
55В плане | CVE-2024-0507Proof of concept | Privilege Escalation by Code Injection in the Management Console in GitHub Enterprise Servergithub · enterprise server · CWE-20 | Высокая8,8 | — | 65,8 % | 16 янв. 2024 г. |
46В плане | CVE-2024-9487Proof of concept | An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassedgithub · enterprise server · CWE-347 | Критическая9,5 | — | 25,6 % | 10 окт. 2024 г. |
45В плане | CVE-2017-18365Готовый эксплойт | The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to egithub · github · CWE-502 | Критическая9,8 | — | 21,2 % | 28 мар. 2019 г. |
41В плане | CVE-2024-4985Эксплойта нет | An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication github · enterprise server · CWE-303 | Критическая10,0 | — | 2,6 % | 20 мая 2024 г. |
40В плане | CVE-2022-24724Эксплойта нет | Integer overflow in table parsing extension leads to heap memory corruptiongithub · cmark-gfm · CWE-190 | Критическая9,8 | — | 4,5 % | 3 мар. 2022 г. |
39Наблюдать | CVE-2022-39321Эксплойта нет | GitHub Actions Runner vulnerable to Docker Command Escapinggithub · runner · CWE-78 | Критическая9,9 | — | 1,6 % | 25 окт. 2022 г. |
39Наблюдать | CVE-2020-10516Эксплойта нет | Improper access control in GitHub Enterprise Server leading to privilege escalation of organization membergithub · github · CWE-285 | Критическая9,8 | — | 1,6 % | 3 июн. 2020 г. |
39Наблюдать | CVE-2022-46255Эксплойта нет | Improper Limitation of a Pathname to a Restricted Directory in GitHub Enterprise Server leading to RCEgithub · enterprise server · CWE-22 | Критическая9,8 | — | 1,5 % | 14 дек. 2022 г. |
39Наблюдать | CVE-2024-22051Эксплойта нет | CommonMarker Integer Overflow Vulnerabilitygithub · cmark-gfm · CWE-190 | Критическая9,8 | — | 1,5 % | 4 янв. 2024 г. |
39Наблюдать | CVE-2022-23739Эксплойта нет | Incorrect authorization check in GitHub Enterprise Server leading to escalation of privileges in GraphQL API requests from GitHub Apps using scoped user-to-servgithub · enterprise server · CWE-863 | Критическая9,8 | — | 1,2 % | 17 янв. 2023 г. |
39Наблюдать | CVE-2021-22869Эксплойта нет | Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control groupgithub · enterprise server · CWE-668 | Критическая9,8 | — | 1,2 % | 24 сент. 2021 г. |
39Наблюдать | CVE-2015-10031Эксплойта нет | purpleparrots 491-Project Highscore update.php sql injectiongithub · 491-project · CWE-89 | Критическая9,8 | — | 0,7 % | 8 янв. 2023 г. |
38Наблюдать | CVE-2024-6800Эксплойта нет | An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identitygithub · enterprise server · CWE-347 | Критическая9,5 | — | 1,5 % | 20 авг. 2024 г. |
38Наблюдать | CVE-2024-52308Эксплойта нет | Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computergithub · cli · CWE-77 | Критическая9,6 | — | 0,9 % | 14 нояб. 2024 г. |
37Наблюдать | CVE-2024-1374Эксплойта нет | Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Consolegithub · enterprise server · CWE-20 | Критическая9,1 | — | 2,6 % | 13 февр. 2024 г. |
37Наблюдать | CVE-2024-1355Эксплойта нет | Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Consolegithub · enterprise server · CWE-20 | Критическая9,1 | — | 2,4 % | 13 февр. 2024 г. |
37Наблюдать | CVE-2024-1378Эксплойта нет | Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Consolegithub · enterprise server · CWE-20 | Критическая9,1 | — | 2,3 % | 13 февр. 2024 г. |
37Наблюдать | CVE-2024-1359Эксплойта нет | Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Consolegithub · enterprise server · CWE-20 | Критическая9,1 | — | 2,3 % | 13 февр. 2024 г. |
37Наблюдать | CVE-2024-1369Эксплойта нет | Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Consolegithub · enterprise server · CWE-20 | Критическая9,1 | — | 2,3 % | 13 февр. 2024 г. |
37Наблюдать | CVE-2024-1372Эксплойта нет | Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Consolegithub · enterprise server · CWE-20 | Критическая9,1 | — | 2,3 % | 13 февр. 2024 г. |
36Наблюдать | CVE-2020-10518Эксплойта нет | Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Servergithub · github · CWE-77 | Высокая8,8 | — | 3,7 % | 27 авг. 2020 г. |
36Наблюдать | CVE-2020-10519Эксплойта нет | Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Servergithub · github · CWE-77 | Высокая8,8 | — | 3,1 % | 3 мар. 2021 г. |
36Наблюдать | CVE-2021-22864Эксплойта нет | Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Servergithub · enterprise server · CWE-77 | Высокая8,8 | — | 2,5 % | 23 мар. 2021 г. |
36Наблюдать | CVE-2021-41599Эксплойта нет | Improper control flow in GitHub Enterprise Server hosted Pages leads to remote code executiongithub · enterprise server · CWE-77 | Высокая8,8 | — | 2,2 % | 17 февр. 2022 г. |
- CVE-2024-020061На этой неделе
Unsafe Reflection in Github Enterprise Server leading to Command Injection
КритическаяCVSS 9,8Proof of conceptEPSS 72 %github · enterprise server16 янв. 2024 г.
- CVE-2024-050755В плане
Privilege Escalation by Code Injection in the Management Console in GitHub Enterprise Server
ВысокаяCVSS 8,8Proof of conceptEPSS 66 %github · enterprise server16 янв. 2024 г.
- CVE-2024-948746В плане
An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed
КритическаяCVSS 9,5Proof of conceptEPSS 26 %github · enterprise server10 окт. 2024 г.
- CVE-2017-1836545В плане
The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to e
КритическаяCVSS 9,8Готовый эксплойтEPSS 21 %github · github28 мар. 2019 г.
- CVE-2024-498541В плане
An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %github · enterprise server20 мая 2024 г.
- CVE-2022-2472440В плане
Integer overflow in table parsing extension leads to heap memory corruption
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %github · cmark-gfm3 мар. 2022 г.
- CVE-2022-3932139Наблюдать
GitHub Actions Runner vulnerable to Docker Command Escaping
КритическаяCVSS 9,9Эксплойта нетEPSS 2 %github · runner25 окт. 2022 г.
- CVE-2020-1051639Наблюдать
Improper access control in GitHub Enterprise Server leading to privilege escalation of organization member
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %github · github3 июн. 2020 г.
- CVE-2022-4625539Наблюдать
Improper Limitation of a Pathname to a Restricted Directory in GitHub Enterprise Server leading to RCE
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %github · enterprise server14 дек. 2022 г.
- CVE-2024-2205139Наблюдать
CommonMarker Integer Overflow Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %github · cmark-gfm4 янв. 2024 г.
- CVE-2022-2373939Наблюдать
Incorrect authorization check in GitHub Enterprise Server leading to escalation of privileges in GraphQL API requests from GitHub Apps using scoped user-to-serv
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %github · enterprise server17 янв. 2023 г.
- CVE-2021-2286939Наблюдать
Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control group
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %github · enterprise server24 сент. 2021 г.
- CVE-2015-1003139Наблюдать
purpleparrots 491-Project Highscore update.php sql injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %github · 491-project8 янв. 2023 г.
- CVE-2024-680038Наблюдать
An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity
КритическаяCVSS 9,5Эксплойта нетEPSS 2 %github · enterprise server20 авг. 2024 г.
- CVE-2024-5230838Наблюдать
Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %github · cli14 нояб. 2024 г.
- CVE-2024-137437Наблюдать
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %github · enterprise server13 февр. 2024 г.
- CVE-2024-135537Наблюдать
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %github · enterprise server13 февр. 2024 г.
- CVE-2024-137837Наблюдать
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %github · enterprise server13 февр. 2024 г.
- CVE-2024-135937Наблюдать
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %github · enterprise server13 февр. 2024 г.
- CVE-2024-136937Наблюдать
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %github · enterprise server13 февр. 2024 г.
- CVE-2024-137237Наблюдать
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %github · enterprise server13 февр. 2024 г.
- CVE-2020-1051836Наблюдать
Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Server
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %github · github27 авг. 2020 г.
- CVE-2020-1051936Наблюдать
Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Server
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %github · github3 мар. 2021 г.
- CVE-2021-2286436Наблюдать
Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Server
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %github · enterprise server23 мар. 2021 г.
- CVE-2021-4159936Наблюдать
Improper control flow in GitHub Enterprise Server hosted Pages leads to remote code execution
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %github · enterprise server17 февр. 2022 г.