BlackTreeCVE IntelligenceOfficial source evidencedocs.github.comVersioned article
Official source article · docs.github.com
Release notes - GitHub Enterprise Server 3.8 Docs
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherdocs.github.com
Article IDNo stable ID in source URL
Verified snapshot29 Sept 2026, 02:41 UTC
Linked CVEs31
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2024-1374Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
- CVE-2024-1372Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
- CVE-2024-1359Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
- CVE-2024-1082Path traversal vulnerability in GitHub Enterprise Server that allowed arbitrary file read with a specially crafted GitHub Pages artifact upload
- CVE-2024-1354Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
- CVE-2023-6746Sensitive Information in Log File in GitHub Enterprise Server
- CVE-2024-2469Remote Code Execution in GitHub Enterprise Server Allowed Administrators to gain SSH access to the appliance
- CVE-2024-1355Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
- CVE-2023-22381Code injection in GitHub Enterprise Server leading to arbitrary environment variables in GitHub Actions
- CVE-2023-23762Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling
- CVE-2023-23761Improper authentication vulnerability in GitHub Enterprise Server leading to modification of secret gists
- CVE-2023-46646Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get a check run" API endpoint
- CVE-2023-6804Improper Privilege Management allows for arbitrary workflows to be run
- CVE-2024-0507Privilege Escalation by Code Injection in the Management Console in GitHub Enterprise Server
- CVE-2023-23764Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling
- CVE-2023-23763Information disclosure in GitHub Enterprise Server leading to private repository leakage
- CVE-2023-23765Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling
- CVE-2023-46645Path traversal in GitHub Enterprise Server leading to arbitrary file reading when building a GitHub Pages site
- CVE-2023-6802Sensitive Information in Log File in GitHub Enterprise Server
- CVE-2024-2443Improper input validation vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console
- CVE-2024-1369Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
- CVE-2024-1378Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
- CVE-2023-51379Incorrect Authorization for Issue Comments in GitHub Enterprise Server
- CVE-2023-51380Incorrect Authorization allows Read Access to Issue Comments in GitHub Enterprise Server
- CVE-2023-46649Race Condition allows Administrative Access on Organization Repositories
- CVE-2023-46648Insufficient Entropy in GitHub Enterprise Server Management Console Invitation Token
- CVE-2023-46647Improper Privilege Management in GitHub Enterprise Server management console leads to privilege escalation
- CVE-2023-6803Race Condition allows Unauthorized Outside Collaborator
- CVE-2023-6690GitHub Enterprise Server — Time-of-check Time-of-use (TOCTOU) Race Condition
- CVE-2024-1084GitHub Enterprise Server — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2024-0200Unsafe Reflection in Github Enterprise Server leading to Command Injection
Source and provenance
Original title: Release notes - GitHub Enterprise Server 3.8 Docs. Captured 29 Sept 2026, 02:41 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗