logo

SAML Exploit Github: CVE-2024-6800

ID: 0a556381-72ba-5039-b5ef-428e65a8c411

STIX ID: report--0a556381-72ba-5039-b5ef-428e65a8c411

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2024-10-18

Date Updated: 2026-07-17

...
...

GitHub Enterprise Server (GHES) is affected by CVE-2024-6800, a critical XML signature wrapping vulnerability enabling forged SAML responses that could grant attackers administrator access to GHES instances, potentially exposing or altering source code and compromising supply chains. GitHub has issued patches (including fixes in 3.13.3) and organizations are urged to upgrade immediately and monitor for suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.