GitHub Alerts On Critical Vulnerability In Self-Hosted Environments
ID: 0d509ed9-8e71-56eb-a52f-6789d67391a7
STIX ID: report--0d509ed9-8e71-56eb-a52f-6789d67391a7
Feed Name: Cyble Blog
Threat Score
GitHub Enterprise Server has a critical vulnerability (CVE-2024-9487, CVSS 9.5) that stems from improper verification of cryptographic signatures and can allow SAML SSO bypass and unauthorized user provisioning; affected GHES versions are listed and GitHub has released a patch, with organizations urged to apply updates and follow mitigation best practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
