logo

GitHub Alerts On Critical Vulnerability In Self-Hosted Environments

ID: 0d509ed9-8e71-56eb-a52f-6789d67391a7

STIX ID: report--0d509ed9-8e71-56eb-a52f-6789d67391a7

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2024-10-17

Date Updated: 2026-07-20

...
...

GitHub Enterprise Server has a critical vulnerability (CVE-2024-9487, CVSS 9.5) that stems from improper verification of cryptographic signatures and can allow SAML SSO bypass and unauthorized user provisioning; affected GHES versions are listed and GitHub has released a patch, with organizations urged to apply updates and follow mitigation best practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.