logo

GitHub patches critical vulnerability in its Enterprise Servers

ID: d64cd53e-2ece-5ab3-9b02-8d5933188df6

STIX ID: report--d64cd53e-2ece-5ab3-9b02-8d5933188df6

Feed Name: CyberScoop

Threat Score
75/100

Date Published: 2024-10-16

Date Updated: 2026-04-21

Author: Christian Vasquez

...
...

GitHub released an Enterprise Server update addressing CVE-2024-9487, a critical (CVSS 9.5) SAML authentication bypass affecting on‑prem GitHub Enterprise installations that could allow forged SAML assertions to grant unauthorized access to repositories and sensitive data; the update also corrects a regression of a prior critical vulnerability (CVE-2024-4985) and other security issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.