By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: GitHub warns of SAML auth bypass flaw in Enterprise Server
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > GitHub warns of SAML auth bypass flaw in Enterprise Server
Tech News

GitHub warns of SAML auth bypass flaw in Enterprise Server

By admin 3 Min Read
Share
SHARE

GitHub has fixed a maximum severity (CVSS v4 score: 10.0) authentication bypass vulnerability tracked as CVE-2024-4986, which impacts GitHub Enterprise Server (GHES) instances using SAML single sign-on (SSO) authentication.

Exploiting the flaw would allow a threat actor to forge a SAML response and gain administrator privileges, providing unrestricted access to all of the instance’s contents without requiring any authentication.

GHES is a self-hosted version of GitHub designed for organizations that prefer to store repositories on their own servers or private cloud environments.

It caters to the needs of large enterprises or development teams that require greater control over their assets, entities handling sensitive or proprietary data, organizations with high-performance needs, and users requiring offline access capabilities.

The flaw, which was submitted to GitHub’s Bug Bounty program, only impacts instances utilizing Security Assertion Markup Language (SAML) SSO with encrypted assertions. This optional feature protects data against interception (man-in-the-middle attacks).

“On instances that use SAML single sign-on (SSO) authentication with the optional encrypted assertions feature, an attacker could forge a SAML response to provision and/or gain access to a user with administrator privileges.” – GitHub.

Due to encrypted assertions not being the default setting on GHES, CVE-2024-4986 only impacts instances whose administrators have enabled the security feature.

The vulnerability has been fixed in GHEL versions 3.12.4, 3.11.10, 3.10.12, and 3.9.15, all released yesterday, on May 20.

Known issues with the update include:

  • Custom firewall rules are wiped.
  • “No such object” error during configuration validation for Notebook and Viewscreen services. (can be ignored)
  • Management Console root admin account does not unlock automatically after lockout. (requires SSH access to unlock)
  • TLS-enabled log forwarding fails as CA bundles uploaded using ghe-ssl-ca-certificate-install are not respected.
  • The mbind: Operation not permitted error in MySQL logs can be ignored.
  • AWS instances may lose system time synchronization after a reboot.
  • All client IPs appear as 127.0.0.1 in audit logs when using the X-Forwarded-For header behind a load balancer.
  • Large .adoc files may not render in the web UI but are available as plaintext.
  • Backup restoration with ghe-restore may fail if Redis hasn’t restarted properly.
  • Repositories imported using ghe-migrator do not track Advanced Security contributions correctly.
  • GitHub Actions workflows for GitHub Pages may fail; fix requires specific SSH commands. (fix provided in the bulletin)

Despite those issues, those using the vulnerable configuration (SAML SSO + encrypted assertions) should immediately move to a safe GHEL version.

You Might Also Like

TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials

Why cybersecurity needs to adapt in the age of AI

A School District Tried to Help Train Waymos to Stop for School Buses. It Didn’t Work

Google Pixel 10a Review: This is Fine

Galaxy Z Fold 8 vs. Z Fold 8 Wide: What’s the Difference?

TAGGED: Authentication Bypass, GHES, GitHub, SAML, SSO, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article Tech View: Nifty stuck between 22,400-22,600. What should traders do on Wednesday
Next Article Google Taps AI to Show Shoppers How Clothes Fit Different Bodies
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Russia was expecting a windfall from soaring oil prices, but relentless Ukrainian drone attacks are devastating nearly half its export capacity
Business
Walmart-backed OnePay adds tokens in push to serve ‘new to crypto’ customers
Crypto
Damon and Baby review: hellishly fun new Metroidvania shooter
Gaming News
Explora Journeys becomes latest cruise line to be impacted by Middle East war
Travel
TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials
Tech News
Why cybersecurity needs to adapt in the age of AI
Tech News
Is Europe sleepwalking into its worst gas crisis since 2022?
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Russia was expecting a windfall from soaring oil prices, but relentless Ukrainian drone attacks are devastating nearly half its export capacity

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Russia was expecting a windfall from soaring oil prices, but relentless Ukrainian drone attacks are devastating nearly half its export capacity
March 29, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?