A vulnerability in GitHub Enterprise Server that grants admin rights without authentication

In the corrective updates of GitHub Enterprise Server versions 3.12.4, 3.11.10, 3.10.12, and 3.9.15, designed for deployment on-premises for isolated collaborative development environments based on GitHub technologies, a vulnerability (CVE-2024-4985) has been identified that allows administrative access without authentication. The issue only manifests in configurations with a single sign-on based on SAML technology, where message encryption from identity providers ('encrypted assertions') is enabled. By default, this mode is disabled but is presented as an additional security measure that can be activated in the settings 'Settings/Authentication/Require encrypted assertions'.

The vulnerabilities have been assigned a critical severity level (10 out of 10). No account is required to carry out the attack. Details about the exploitation of the vulnerability are not provided, only mentioning that the attack is conducted through SAML response forgery. Information about the vulnerability was obtained from a participant in the GitHub Bug Bounty program, which rewards the discovery of security issues.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster