logo

Critical GitHub Enterprise Server Authentication Bypass bug. Fix it now!

ID: 36fb588d-6483-5e07-9371-59dd61d2f756

STIX ID: report--36fb588d-6483-5e07-9371-59dd61d2f756

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2024-05-22

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

GitHub Enterprise Server (GHES) had a critical authentication bypass (CVE-2024-4985, CVSS 10.0) affecting instances using SAML SSO with encrypted assertions, allowing forged SAML responses to provision or access admin accounts; fixes were released in GHES versions 3.9.15, 3.10.12, 3.11.10, and 3.12.4, and encrypted assertions are not enabled by default.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.