ZeroHour
CyberScooppublished ()ingested @chrismvasq1

GitHub patches critical vulnerability in its Enterprise Servers

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-4985
An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional en

An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional encrypted assertions feature. This vulnerability allowed an attacker to forge a SAML response to provision and/or gain access to a user with site administrator privileges. Exploitation of this vulnerability would allow unauthorized access to the instance without requiring prior authentication. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.13.0 and was fixed in versions 3.9.15, 3.10.12, 3.11.10 and 3.12.4. This vulnerability was reported via the GitHub Bug Bounty program.

NVD description · AI analysis pending
10.03%
  • github enterprise server
CVE-2024-9487
Improper SAML Signature Verification Bypasses SSO in GitHub Enterprise Server

CVE-2024-9487 is an improper verification of cryptographic signature flaw (CWE-347) in GitHub Enterprise Server that allows SAML SSO authentication to be bypassed. Exploitation requires the encrypted assertions feature to be enabled, direct network access to the instance, and a signed SAML response or metadata document supplied by the attacker. A successful attack results in unauthorized provisioning of users and unauthorized access to the instance. All GitHub Enterprise Server versions prior to 3.15 are affected, with fixes shipped in 3.11.16, 3.12.10, 3.13.5, and 3.14.2. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but EPSS assigns a 25.6% probability of exploitation within 30 days (98th percentile), indicating elevated risk.

Do: Upgrade GitHub Enterprise Server to version 3.14.2, 3.13.5, 3.12.10, or 3.11.16 (or any 3.15+ release). Administrators who cannot patch immediately should verify whether SAML SSO with encrypted assertions is enabled, limit direct network access to the instance, and review user provisioning logs for unexpected accounts. This flaw was reported via the GitHub Bug Bounty program and is not yet in CISA KEV.

9.526%
  • GitHub Enterprise Server All versions prior to 3.15; fixed in 3.11.16, 3.12.10, 3.13.5, and 3.14.2
largeTens of thousands of self-hosted GHES instances, of which only a subset (SAML SSO with encrypted assertions enabled and directly reachable) is exploitable
CVE-2024-9539
An information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allowing the attacker to retrieve metadata in

An information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allowing the attacker to retrieve metadata information of a user who clicks on the URL and further exploit it to create a convincing phishing page. This required the attacker to upload malicious SVG files and phish a victim user to click on that uploaded asset URL. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versions 3.14.2, 3.13.5, 3.12.10, 3.11.16. This vulnerability was reported via the GitHub Bug Bounty program.

NVD description · AI analysis pending
5.7<1%
  • github enterprise server
Full article640 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The “severe” flaw could allow attackers full access to instances.

Listen to this article

0:00

Learn more.

PARIS, FRANCE - JUNE 04: In this photo illustration the GitHub logo is seen on the screen of an iPhone in front of a computer screen showing a Microsoft logo on June 04, 2018 in Paris, France. (Photo Illustration by Chesnot/Getty Images)

GitHub’s latest Enterprise Server update fixes a critical vulnerability that allows authentication bypass for on-premise deployments, according to the company.

The bug — CVE-2024-9487 — impacts GitHub’s enterprise product and does not affect its software-as-a-service products, according to the company’s release. The Microsoft-owned company said the bug, which is a 9.5 on the CVSS scale, would allow hackers to bypass a method typically used by companies to verify employee identities using single sign-on called Security Assertion Markup Language (SAML).

Chris Hatter, chief technology officer of the application security company Qwiet.Ai, called the vulnerability “severe” and said that organizations should ensure they understand their relevant network architectures. 

Hatter said companies should block any “routes to this access” and ensure that they have “telemetry to be able to understand who is accessing these resources by whom and from where.”

Hatter said a typical attack would likely require a malicious actor to already have access to internal networks in order to use the vulnerability. He cautioned that some organizations might publish Enterprise Servers to the open internet, but it would be unusual. 

The bug forges the authentication request that identity providers use to verify a person is signing onto an approved service. Most people have multiple identities for work — a recent report from Push Security noted that companies have on average 15 identities per employee — and SAML SSOs help organizations manage authorization and access.

Hatter said GitHub Enterprise Servers could be a “treasure trove of information” for hackers. Accessed instances could include “source code, architectural documents, information about developers,” which could be useful for espionage, social engineering attacks, and IP theft, among other acts.

“If you have access to the source code and you have administrative privileges into the source code management systems, theoretically you could start to manipulate that source code and implement a back door,” Hatter said.

GitHub’s latest update fixes a regression of CVE-2024-4985, a vulnerability with a 10.0 CVSS score that was first patched by GitHub in May.

The Oct. 6 update had two other security fixes: a bug in SVG assets that allows for possible metadata retrieval — CVE-2024-9539 — and a functionality from the management console that could allow sensitive data exposure in HTML forms was removed.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/github-enterprise-vulnerability-sso-saml/