logo

Critical GitHub Enterprise Server Flaw Allows Authentication Bypass

ID: 60889327-81db-57ea-bd24-65b20a6d5358

STIX ID: report--60889327-81db-57ea-bd24-65b20a6d5358

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2024-05-21

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

GitHub Enterprise Server (GHES) had a maximum-severity authentication bypass vulnerability (CVE-2024-4985, CVSS 10.0) where an attacker could forge SAML responses for instances using SAML SSO with the optional encrypted assertions feature, potentially provisioning or gaining admin access; the issue affects GHES versions prior to 3.13.0 and is addressed in 3.9.15, 3.10.12, 3.11.10 and 3.12.4 — organizations using vulnerable versions are advised to update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.