GitHub patches critical vulnerability in its Enterprise Servers
ID: d64cd53e-2ece-5ab3-9b02-8d5933188df6
STIX ID: report--d64cd53e-2ece-5ab3-9b02-8d5933188df6
Feed Name: CyberScoop
Threat Score
GitHub released an Enterprise Server update addressing CVE-2024-9487, a critical (CVSS 9.5) SAML authentication bypass affecting on‑prem GitHub Enterprise installations that could allow forged SAML assertions to grant unauthorized access to repositories and sensitive data; the update also corrects a regression of a prior critical vulnerability (CVE-2024-4985) and other security issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
