EXECUTIVE SUMMARY:
GitHub has released security updates for Enterprise Server (GHES) addressing critical vulnerabilities, including CVE-2024-9487, which allows attackers to bypass SAML single sign-on authentication. This flaw permits unauthorized provisioning of users, potentially granting unauthorized access to the instance due to improper verification of cryptographic signatures. Additionally, an information disclosure vulnerability, CVE-2024-9539, has been identified, which could allow attackers to retrieve metadata from victim users through malicious SVG asset links. The vulnerability is related to a regression stemming from CVE-2024-4985, which was patched earlier, and is similar in severity to CVE-2024-6800, a critical flaw that could be exploited to gain site administrator privileges. Organizations operating vulnerable self-hosted versions of GHES are strongly encouraged to upgrade to the versions to mitigate these security risks.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
GitHub has released security updates for Enterprise Server (GHES) addressing critical vulnerabilities, including CVE-2024-9487, which allows attackers to bypass SAML single sign-on authentication. This flaw permits unauthorized provisioning of users, potentially granting unauthorized access to the instance due to improper verification of cryptographic signatures. Additionally, an information disclosure vulnerability, CVE-2024-9539, has been identified, which could allow attackers to retrieve metadata from victim users through malicious SVG asset links. The vulnerability is related to a regression stemming from CVE-2024-4985, which was patched earlier, and is similar in severity to CVE-2024-6800, a critical flaw that could be exploited to gain site administrator privileges. Organizations operating vulnerable self-hosted versions of GHES are strongly encouraged to upgrade to the versions to mitigate these security risks.[emaillocker id="1283"]
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/10/github-patches-critical-flaw-in.html