BlackTreeCVE IntelligenceOfficial source evidencedocs.github.comVersioned article
Official source article · docs.github.com
Release notes - GitHub Enterprise Server 3.13 Docs
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherdocs.github.com
Article IDNo stable ID in source URL
Verified snapshot28 Sept 2026, 20:28 UTC
Linked CVEs22
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2025-3509Pre-Receive Hook Remote Code Execution vulnerability was identified in GitHub Enterprise Server that allowing Privilege Escalation
- CVE-2025-3124Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized access to private repository names
- CVE-2025-23369Improper Verification of Cryptographic Signature in GitHub Enterprise Server Allows Signature Spoofing by Improper Validation
- CVE-2024-10001Code Injection Vulnerability in GitHub Enterprise Server Allows Arbitrary Code Execution via Message Handling
- CVE-2024-10007Pre-Receive Hook Path Collision Vulnerability in GitHub Enterprise Server Allowing Privilege Escalation
- CVE-2024-10824Authorization Bypass Vulnerability was Identified in GitHub Enterprise Server that Allowed Unauthorized Internal Users to Access Secret Scanning Alert Data
- CVE-2024-8810Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed GitHub Apps to grant themselves write access
- CVE-2024-9539GitHub GitHub Enterprise Server — Exposure of Sensitive Information to an Unauthorized Actor
- CVE-2024-9487An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed when the encrypted assertions feature was enabled
- CVE-2024-8770GitHub GitHub Enterprise Server — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2024-8263An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags
- CVE-2024-6800GitHub GitHub Enterprise Server — Improper Verification of Cryptographic Signature
- CVE-2024-6337Incorrect Authorization allows read access to issues in GitHub Enterprise Server
- CVE-2024-7711An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, and labels of any issue inside a public repository
- CVE-2024-6395GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Deploy Keys
- CVE-2024-6336Security misconfiguration was identified in GitHub Enterprise Server that allowed sensitive data exposure
- CVE-2024-5816Improper authorization allows persistent access in GitHub Enterprise Server
- CVE-2024-5817Improper authorization allows read access to issue content in GitHub Enterprise Server
- CVE-2024-5815Cross Site Request Forgery was identified in GitHub Enterprise Server that allowed write in a user owned repository
- CVE-2024-5815Cross Site Request Forgery was identified in GitHub Enterprise Server that allowed write in a user owned repository
- CVE-2024-5795Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed resource exhaustion
- CVE-2024-5566Improper Privilege Management allows for access to unauthorized repository content during migration
Source and provenance
Original title: Release notes - GitHub Enterprise Server 3.13 Docs. Captured 28 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗