296,733
Total vulnerabilities in the database
Improper privilege management allowed arbitrary workflows to be committed and run using an improperly scoped PAT. To exploit this, a workflow must have already existed in the target repo. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.
| Software | From | Fixed in |
|---|---|---|
| github / enterprise_server | 3.10.0 | 3.10.4 |
| github / enterprise_server | 3.9.0 | 3.9.7 |
| github / enterprise_server | 3.8.0 | 3.8.12 |
| github / enterprise_server | 3.11.0 | 3.11.0.x |