ZeroHour

CVE-2024-9487

large2

Improper SAML Signature Verification Bypasses SSO in GitHub Enterprise Server

CVSS 4.0
9.5 critical
EPSS
26%p98
Published
()
Modified
AI analysis

CVE-2024-9487 is an improper verification of cryptographic signature flaw (CWE-347) in GitHub Enterprise Server that allows SAML SSO authentication to be bypassed. Exploitation requires the encrypted assertions feature to be enabled, direct network access to the instance, and a signed SAML response or metadata document supplied by the attacker. A successful attack results in unauthorized provisioning of users and unauthorized access to the instance. All GitHub Enterprise Server versions prior to 3.15 are affected, with fixes shipped in 3.11.16, 3.12.10, 3.13.5, and 3.14.2. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but EPSS assigns a 25.6% probability of exploitation within 30 days (98th percentile), indicating elevated risk.

What to do: Upgrade GitHub Enterprise Server to version 3.14.2, 3.13.5, 3.12.10, or 3.11.16 (or any 3.15+ release). Administrators who cannot patch immediately should verify whether SAML SSO with encrypted assertions is enabled, limit direct network access to the instance, and review user provisioning logs for unexpected accounts. This flaw was reported via the GitHub Bug Bounty program and is not yet in CISA KEV.

Affected
GitHub Enterprise ServerAll versions prior to 3.15; fixed in 3.11.16, 3.12.10, 3.13.5, and 3.14.2
Estimated exposure
largeTens of thousands of self-hosted GHES instances, of which only a subset (SAML SSO with encrypted assertions enabled and directly reachable) is exploitable — Estimate based on the deployment pattern of GitHub Enterprise Server as the self-hosted edition used by thousands of enterprises on-premises, narrowed by the preconditions that SAML with encrypted assertions must be enabled and the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning of users and access to the instance. Exploitation required the encrypted assertions feature to be enabled, and the attacker would require direct network access as well as a signed SAML response or metadata document. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.15 and was fixed in versions 3.11.16, 3.12.10, 3.13.5, and 3.14.2. This vulnerability was reported via the GitHub Bug Bounty program.

Vendors
github
Products
enterprise server
Weakness
CWE-347
Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:M/U:Red

In the news