It's true, Github Enterprise Install might merit a CVE. I don't think that the Rails default behavior (documented since 2008?) or Github (as you say, not distributed) would warrant one.
But, while I've done a fair amount of Rails, I'm not the most in touch with CVEs.