GitHub Patches Critical Flaw in Enterprise Server Allowing Unauthorized Instance Access
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-4985 | An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional en An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional encrypted assertions feature. This vulnerability allowed an attacker to forge a SAML response to provision and/or gain access to a user with site administrator privileges. Exploitation of this vulnerability would allow unauthorized access to the instance without requiring prior authentication. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.13.0 and was fixed in versions 3.9.15, 3.10.12, 3.11.10 and 3.12.4. This vulnerability was reported via the GitHub Bug Bounty program. NVD description · AI analysis pending | 10.0 | 3% |
| — | ||
| CVE-2024-6800 | An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed signed federation metadata XML. This vulnerability allowed an attacker with direct network access to GitHub Enterprise Server to forge a SAML response to provision and/or gain access to a user with site administrator privileges. Exploitation of this vulnerability would allow unauthorized access to the instance without requiring prior authentication. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versions 3.13.3, 3.12.8, 3.11.14, and 3.10.16. This vulnerability was reported via the GitHub Bug Bounty program. NVD description · AI analysis pending | 9.5 | 2% |
| — | ||
| CVE-2024-9487 | Improper SAML Signature Verification Bypasses SSO in GitHub Enterprise Server CVE-2024-9487 is an improper verification of cryptographic signature flaw (CWE-347) in GitHub Enterprise Server that allows SAML SSO authentication to be bypassed. Exploitation requires the encrypted assertions feature to be enabled, direct network access to the instance, and a signed SAML response or metadata document supplied by the attacker. A successful attack results in unauthorized provisioning of users and unauthorized access to the instance. All GitHub Enterprise Server versions prior to 3.15 are affected, with fixes shipped in 3.11.16, 3.12.10, 3.13.5, and 3.14.2. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but EPSS assigns a 25.6% probability of exploitation within 30 days (98th percentile), indicating elevated risk. Do: Upgrade GitHub Enterprise Server to version 3.14.2, 3.13.5, 3.12.10, or 3.11.16 (or any 3.15+ release). Administrators who cannot patch immediately should verify whether SAML SSO with encrypted assertions is enabled, limit direct network access to the instance, and review user provisioning logs for unexpected accounts. This flaw was reported via the GitHub Bug Bounty program and is not yet in CISA KEV. | 9.5 | 26% |
| largeTens of thousands of self-hosted GHES instances, of which only a subset (SAML SSO with encrypted assertions enabled and directly reachable) is exploitable | ||
| CVE-2024-9539 | An information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allowing the attacker to retrieve metadata in An information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allowing the attacker to retrieve metadata information of a user who clicks on the URL and further exploit it to create a convincing phishing page. This required the attacker to upload malicious SVG files and phish a victim user to click on that uploaded asset URL. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versions 3.14.2, 3.13.5, 3.12.10, 3.11.16. This vulnerability was reported via the GitHub Bug Bounty program. NVD description · AI analysis pending | 5.7 | <1% |
| — |
Full article264 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 16, 2024Enterprise Security / Vulnerability
GitHub has released security updates for Enterprise Server (GHES) to address multiple issues, including a critical bug that could allow unauthorized access to an instance.
The vulnerability, tracked as CVE-2024-9487, carries a CVS score of 9.5 out of a maximum of 10.0
"An attacker could bypass SAML single sign-on (SSO) authentication with the optional encrypted assertions feature, allowing unauthorized provisioning of users and access to the instance, by exploiting an improper verification of cryptographic signatures vulnerability in GitHub Enterprise Server," GitHub said in an alert.
The Microsoft-owned company characterized the flaw as a regression that was introduced as part of follow-up remediation from CVE-2024-4985 (CVSS score: 10.0), a maximum severity vulnerability that was patched back in May 2024.
Also fixed by GitHub are two other shortcomings -
- CVE-2024-9539 (CVSS score: 5.7) - An information disclosure vulnerability that could enable an attacker to retrieve metadata belonging to a victim user upon clicking malicious URLs for SVG assets
- A sensitive data exposure in HTML forms in the management console (no CVE)
All three security vulnerabilities have been addressed in Enterprise Server versions 3.14.2, 3.13.5, 3.12.10, and 3.11.16.
Back in August, GitHub also patched a critical security defect (CVE-2024-6800, CVSS score: 9.5) that could be abused to gain site administrator privileges.
Organizations that are running a vulnerable self-hosted version of GHES are highly advised to update to the latest version to safeguard against potential security threats.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/10/github-patches-critical-flaw-in.html