GitHub Authentication Bypass Opens Enterprise Server to Attackers
ID: da041a1d-e065-5b08-899e-a846e87a198e
STIX ID: report--da041a1d-e065-5b08-899e-a846e87a198e
Feed Name: Dark Reading
Threat Score
**Executive summary:** A maximum-critical authentication-bypass vulnerability (CVE-2024-4985, CVSS 10) in GitHub Enterprise Server using SAML SSO with encrypted assertions allows an attacker to forge SAML responses to gain or provision site administrator privileges; affected versions are prior to 3.13.0 and emergency fixes were issued for several 3.9–3.12 builds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
