logo

GitHub Authentication Bypass Opens Enterprise Server to Attackers

ID: da041a1d-e065-5b08-899e-a846e87a198e

STIX ID: report--da041a1d-e065-5b08-899e-a846e87a198e

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-05-22

Date Updated: 2026-05-05

Author: Dark Reading Staff

...
...

**Executive summary:** A maximum-critical authentication-bypass vulnerability (CVE-2024-4985, CVSS 10) in GitHub Enterprise Server using SAML SSO with encrypted assertions allows an attacker to forge SAML responses to gain or provision site administrator privileges; affected versions are prior to 3.13.0 and emergency fixes were issued for several 3.9–3.12 builds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.