logo

GitHub warns of SAML auth bypass flaw in Enterprise Server

ID: b426bf57-70ea-569a-92de-eed9166a22a4

STIX ID: report--b426bf57-70ea-569a-92de-eed9166a22a4

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-05-21

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

GitHub patched CVE-2024-4985, a CVSS v4 10.0 authentication bypass in GitHub Enterprise Server (GHES) that allows an attacker to forge SAML responses and obtain administrator privileges on instances using SAML SSO with encrypted assertions; fixes were released on May 20 for GHES 3.12.4, 3.11.10, 3.10.12, and 3.9.15 and affected administrators should update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.