GitHub has fixed a maximum severity (CVSS v4 score: 10.0) auth bypass vulnerability tracked as CVE-2024-4986 , which affects GitHub Enterprise Server (GHES), using SAML single-sign-on (SSO) authentication .
See also: Hackers exploit GitHub and FileZilla to spread Cocktail malware

Exploiting the flaw would allow a malicious actor to create a SAML response and gain administrator, granting unrestricted access to all content without requiring authentication.
The GHES affected by the auth bypass flaw is a self-hosted version of GitHub designed for organizations that prefer to store repositories on their own servers or in private cloud environments.
It meets the needs of large enterprises or development teams that require greater control over their assets, entities that handle sensitive or proprietary data, organizations with high-performance needs, and users that require offline access capabilities.
See also: GitHub comments are being abused to promote malware
The auth bypass flaw, which was submitted to the Bug Bounty , only affects cases using Security Authentication Markup Language (SAML) SSO with encrypted assertions. This optional feature protects data from eavesdropping (man-in-the-middle attacks).

Because encrypted assertions are not the default setting in GHES, CVE-2024-4986 only affects instances where administrators have enabled the security feature. The vulnerability has been patched in GHEL versions 3.12.4, 3.11.10, 3.10.12, and 3.9.15, all of which were released yesterday, May 20.
See also: Malicious Visual Studio projects on GitHub push Keyzetsu
What is GitHub and what are its main functions?
Aside from the Enterprise Server auth bypass flaw, GitHub is an online platform that allows developers to host and manage their code, as well as collaborate with other developers from around the world. It uses the Git version control system, which allows you to track changes to your code and revert to previous versions if needed. One of the core features of GitHub is repositories . These are places where code is stored and can be either public or private. Public repositories are accessible by anyone, while private repositories are accessible only by specific people. The ability to create and manage branches is also an important feature of GitHub. Branches allow developers to work on different versions of code at the same time, without affecting the master version.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
