Critical GitHub Enterprise Server Flaw Allows Authentication Bypass
ID: 60889327-81db-57ea-bd24-65b20a6d5358
STIX ID: report--60889327-81db-57ea-bd24-65b20a6d5358
Feed Name: The Hacker News
Threat Score
GitHub Enterprise Server (GHES) had a maximum-severity authentication bypass vulnerability (CVE-2024-4985, CVSS 10.0) where an attacker could forge SAML responses for instances using SAML SSO with the optional encrypted assertions feature, potentially provisioning or gaining admin access; the issue affects GHES versions prior to 3.13.0 and is addressed in 3.9.15, 3.10.12, 3.11.10 and 3.12.4 — organizations using vulnerable versions are advised to update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
