HomeSecurityVulnerability in GitHub Enterprise Allows Authentication Bypass

Vulnerability in GitHub Enterprise Allows Authentication Bypass

A critical vulnerability identified in GitHub Enterprise Server poses significant security risks by allowing attackers to bypass authentication mechanisms.

See also: PKfail Secure Boot bypass remains a significant risk

GitHub Enterprise Vulnerability

This flaw, identified as CVE-2024-9487, was discovered in the Security Assertion Markup Language (SAML) used by GitHub Enterprise Server.

The vulnerability specifically affects cases where the optional encrypted claims feature is enabled, potentially allowing unauthorized users to access the server.

The GitHub Enterprise vulnerability stems from improper cryptographic signature verification, which could allow an attacker with direct network access and a signed SAML response or metadata document to forge a SAML response. This would allow them to gain administrator-level access without prior authentication. The flaw affects all versions of GitHub Enterprise Server prior to version 3.15 and has been addressed in updates released for versions 3.11.16, 3.12.10, 3.13.5 , and 3.14.2.

See also: Malicious npm packages compromise Roblox systems

GitHub acted quickly to fix this vulnerability after it was disclosed through the Bug Bounty. The company emphasizes that the flaw only affects instances using SAML SSO with encrypted claims enabled—a feature that is not enabled by default—thus limiting the scope of affected users.

Vulnerability in GitHub Enterprise Allows Authentication Bypass

The potential impact of this vulnerability is severe, with a maximum CVSS score of 10 out of 10, highlighting the critical nature of the threat. Exploitation of the vulnerability could lead to unauthorized access to sensitive data and administrative functions within affected GitHub Enterprise Server instances.

Therefore, GitHub urges all users running vulnerable configurations to immediately update their systems to mitigate potential security breaches.

GitHub Enterprise Server is a self-hosted version of GitHub, designed for organizations that require greater control over their repositories and workflows. It gives businesses the flexibility and administrative capabilities to manage their codebases in a secure environment. With GitHub Enterprise Server, teams can leverage all the features of GitHub.com, including pull requests, issues, and project boards, while maintaining compliance with internal policies and regulatory standards. It integrates seamlessly with existing corporate systems and offers strong data protection through customizable security features. This solution is ideal for companies that want to leverage the power of collaborative development on GitHub within their own IT infrastructure.

See also: GitHub: Comments are being abused and promoting Lumma Stealer

In light of this vulnerability, it is recommended that organizations using GitHub Enterprise Server review their SAML SSO configurations and ensure they are running the latest patches to protect against unauthorized access and potential data breaches.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS