Critical GitHub Enterprise Server Authentication Bypass bug. Fix it now!
ID: 36fb588d-6483-5e07-9371-59dd61d2f756
STIX ID: report--36fb588d-6483-5e07-9371-59dd61d2f756
Feed Name: Security Affairs
Threat Score
GitHub Enterprise Server (GHES) had a critical authentication bypass (CVE-2024-4985, CVSS 10.0) affecting instances using SAML SSO with encrypted assertions, allowing forged SAML responses to provision or access admin accounts; fixes were released in GHES versions 3.9.15, 3.10.12, 3.11.10, and 3.12.4, and encrypted assertions are not enabled by default.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
