You probably want to patch this critical GitHub Enterprise Server bug now
ID: f74c9586-bc58-5b4f-9c4a-b908a14344f0
STIX ID: report--f74c9586-bc58-5b4f-9c4a-b908a14344f0
Feed Name: The Register (Security)
GitHub Enterprise Server versions 3.10.x–3.13.x contain a critical SAML authentication vulnerability (CVE-2024-6800, CVSS 9.5) that can allow forged SAML responses to grant administrator access to compromised machines; GitHub has released patches for affected GHES versions and organizations are advised to update immediately. The report also notes two medium-severity fixes (CVE-2024-7711 and CVE-2024-6337) and highlights related research into GitHub Actions artifact token leakage, increasing the risk profile for organizations using these services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
