BlackTreeCVE IntelligenceOfficial source evidencedocs.github.comVersioned article
Official source article · docs.github.com
Release notes - GitHub Enterprise Server 3.9 Docs
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherdocs.github.com
Article IDNo stable ID in source URL
Verified snapshot29 Sept 2026, 02:41 UTC
Linked CVEs41
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2024-1374Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
- CVE-2024-1372Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
- CVE-2024-1359Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
- CVE-2024-1082Path traversal vulnerability in GitHub Enterprise Server that allowed arbitrary file read with a specially crafted GitHub Pages artifact upload
- CVE-2024-1354Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
- CVE-2023-6746Sensitive Information in Log File in GitHub Enterprise Server
- CVE-2024-2469Remote Code Execution in GitHub Enterprise Server Allowed Administrators to gain SSH access to the appliance
- CVE-2024-1355Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
- CVE-2023-46646Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get a check run" API endpoint
- CVE-2023-6804Improper Privilege Management allows for arbitrary workflows to be run
- CVE-2024-0507Privilege Escalation by Code Injection in the Management Console in GitHub Enterprise Server
- CVE-2023-23764Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling
- CVE-2023-23763Information disclosure in GitHub Enterprise Server leading to private repository leakage
- CVE-2023-23765Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling
- CVE-2023-46645Path traversal in GitHub Enterprise Server leading to arbitrary file reading when building a GitHub Pages site
- CVE-2023-6802Sensitive Information in Log File in GitHub Enterprise Server
- CVE-2024-2443Improper input validation vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console
- CVE-2024-1369Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
- CVE-2024-1378Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
- CVE-2023-51379Incorrect Authorization for Issue Comments in GitHub Enterprise Server
- CVE-2023-51380Incorrect Authorization allows Read Access to Issue Comments in GitHub Enterprise Server
- CVE-2023-46649Race Condition allows Administrative Access on Organization Repositories
- CVE-2023-46648Insufficient Entropy in GitHub Enterprise Server Management Console Invitation Token
- CVE-2023-46647Improper Privilege Management in GitHub Enterprise Server management console leads to privilege escalation
- CVE-2023-6803Race Condition allows Unauthorized Outside Collaborator
- CVE-2023-6847Improper Authentication in GitHub Enterprise Server leading to Authentication Bypass for Public Repository Data
- CVE-2023-6690GitHub Enterprise Server — Time-of-check Time-of-use (TOCTOU) Race Condition
- CVE-2024-6395GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Deploy Keys
- CVE-2024-6336Security misconfiguration was identified in GitHub Enterprise Server that allowed sensitive data exposure
- CVE-2024-5816Improper authorization allows persistent access in GitHub Enterprise Server
- CVE-2024-5817Improper authorization allows read access to issue content in GitHub Enterprise Server
- CVE-2024-5795Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed resource exhaustion
- CVE-2024-5746GitHub GitHub Enterprise Server — Server-Side Request Forgery (SSRF)
- CVE-2024-5566Improper Privilege Management allows for access to unauthorized repository content during migration
- CVE-2024-4985An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional encrypted assertions feature
- CVE-2024-3684Improper Privilege Management was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console
- CVE-2024-3646Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console
- CVE-2024-2440Race Condition was identified in GitHub Enterprise Server that allowed maintaining admin permissions
- CVE-2024-1482Improper Authorization in GitHub Enterprise Server allowed unauthorized workflow execution
- CVE-2024-1084GitHub Enterprise Server — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2024-0200Unsafe Reflection in Github Enterprise Server leading to Command Injection
Source and provenance
Original title: Release notes - GitHub Enterprise Server 3.9 Docs. Captured 29 Sept 2026, 02:41 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗