SAML Exploit Github: CVE-2024-6800
ID: 0a556381-72ba-5039-b5ef-428e65a8c411
STIX ID: report--0a556381-72ba-5039-b5ef-428e65a8c411
Feed Name: Cyble Blog
Threat Score
GitHub Enterprise Server (GHES) is affected by CVE-2024-6800, a critical XML signature wrapping vulnerability enabling forged SAML responses that could grant attackers administrator access to GHES instances, potentially exposing or altering source code and compromising supply chains. GitHub has issued patches (including fixes in 3.13.3) and organizations are urged to upgrade immediately and monitor for suspicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
