GitHub Enterprise Server patches 10-outta-10 critical hole
ID: 5fbc4744-a482-5acb-bcad-d55bee2c46b2
STIX ID: report--5fbc4744-a482-5acb-bcad-d55bee2c46b2
Feed Name: The Register (Security)
Threat Score
GitHub patched a critical CVE-2024-4985 in Enterprise Server (CVSS 10) that could let an attacker forge SAML encrypted assertions to provision or gain administrator access on instances using SAML SSO with the optional encrypted assertions feature enabled; the flaw was observed in 3.9.x–3.12.x and is fixed in the 3.13.x branch, with patches released and the issue reported via GitHub's bug bounty program.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
