GitHub Enterprise Server vulnerable to critical auth bypass flaw
ID: 4576aa42-d417-51e8-ad4a-25311d34d9fb
STIX ID: report--4576aa42-d417-51e8-ad4a-25311d34d9fb
Feed Name: Bleeping Computer
**CVE-2024-6800:** A critical XML signature wrapping vulnerability in GitHub Enterprise Server SAML SSO can allow an attacker to forge SAML responses and obtain site-administrator privileges; GitHub published fixes in GHES 3.13.3, 3.12.8, 3.11.14, and 3.10.16 and warned of some post-update service issues. The report highlights ~36,500 GHES instances visible on the internet (many in the US), increasing the potential attack surface, but does not report confirmed active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
