CyberWatch

Critical SAML SSO Vulnerability in GitHub Enterprise Server

By

Matthew Fagan and Alexander Marshall, Access Point Consulting

By

Access Point Consulting

Summary

GitHub has remediated an authentication bypass vulnerability under CVE-2024-4985 (CVSSv4: 10.0). This vulnerability allows an attacker to use SAML single sign-on (SSO) authentication to sign in as a user with administrator privileges. This affects GitHub Enterprise Server (GHES) versions prior to 3.13.0 that use SAML SSO with encrypted assertions.

Impact Assessment

  • CVSS Score: 10.0 (Critical)
  • Affected Versions: GHES prior to 3.13.0
  • Conditions: Only affects instances with SAML SSO and encrypted assertions enabled.

Urgency

This vulnerability requires immediate attention due to its severity and potential for exploitation.

Remediation

  • Fixed Versions: 3.9.15, 3.10.12, 3.11.10, 3.12.4, and upcoming 3.13.0.
  • Upgrade Guide: GitHub Docs


Business Implications

Exploitation could lead to unauthorized access, data exfiltration, and injection of malicious code, resulting in significant data, monetary, and reputational loss.

Recommendations

  • Patch: Upgrade to the latest GHES version immediately.
  • Mitigate: Disable encrypted assertions until the upgrade is completed.

Communication Plan

  • Stakeholders: Inform security teams, IT operations, and executive management about the urgency and impact.
  • Internal Notification: Use provided templates to communicate the required actions to all relevant teams.

Associated Bulletin

For more information or assistance, contact:

Resources

Trending Articles & Security Reports

Resources

CyberWatch

September 18, 2024

Adobe Patched Potential Zero-Day in Reader

Adobe released a patch for a suspected zero-day vulnerability in Adobe Reader, identified as CVE-2024-41869. This vulnerability, a Use After Free (UAF) issue, can lead to arbitrary code execution, system crashes, or the return of unexpected values.

Find out more
September 16, 2024

Why We Need NIST's Post-Quantum Cryptography Standards

Last month, NIST published its first set of post-quantum cryptography (PQC) standards, setting a new benchmark for enterprises, government agencies, and vendors to withstand future cyberattacks from quantum computers. The time to start transitioning is now. Discover what’s at stake with CyberWatch.

Find out more
September 13, 2024

Patch Tuesday for September

Every second Tuesday of the month, Microsoft releases patches to their applications, services, and operating systems. Typically, these patches include a myriad of security fixes and this time around, for September of 2024, 79 different vulnerabilities have been addressed, including 4 zero-day vulnerabilities and 10 critical vulnerabilities.

Find out more