logo

You probably want to patch this critical GitHub Enterprise Server bug now

ID: f74c9586-bc58-5b4f-9c4a-b908a14344f0

STIX ID: report--f74c9586-bc58-5b4f-9c4a-b908a14344f0

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2024-08-21

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

GitHub Enterprise Server versions 3.10.x–3.13.x contain a critical SAML authentication vulnerability (CVE-2024-6800, CVSS 9.5) that can allow forged SAML responses to grant administrator access to compromised machines; GitHub has released patches for affected GHES versions and organizations are advised to update immediately. The report also notes two medium-severity fixes (CVE-2024-7711 and CVE-2024-6337) and highlights related research into GitHub Actions artifact token leakage, increasing the risk profile for organizations using these services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.