logo

GitHub Enterprise Server vulnerable to critical auth bypass flaw

ID: 4576aa42-d417-51e8-ad4a-25311d34d9fb

STIX ID: report--4576aa42-d417-51e8-ad4a-25311d34d9fb

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-08-21

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**CVE-2024-6800:** A critical XML signature wrapping vulnerability in GitHub Enterprise Server SAML SSO can allow an attacker to forge SAML responses and obtain site-administrator privileges; GitHub published fixes in GHES 3.13.3, 3.12.8, 3.11.14, and 3.10.16 and warned of some post-update service issues. The report highlights ~36,500 GHES instances visible on the internet (many in the US), increasing the potential attack surface, but does not report confirmed active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.