Threat Advisory

GitHub Patches Critical Flaw in Enterprise Server Allowing Unauthorized Instance Access

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

GitHub has released security updates for Enterprise Server (GHES) addressing critical vulnerabilities, including CVE-2024-9487, which allows attackers to bypass SAML single sign-on authentication. This flaw permits unauthorized provisioning of users, potentially granting unauthorized access to the instance due to improper verification of cryptographic signatures. Additionally, an information disclosure vulnerability, CVE-2024-9539, has been identified, which could allow attackers to retrieve metadata from victim users through malicious SVG asset links. The vulnerability is related to a regression stemming from CVE-2024-4985, which was patched earlier, and is similar in severity to CVE-2024-6800, a critical flaw that could be exploited to gain site administrator privileges. Organizations operating vulnerable self-hosted versions of GHES are strongly encouraged to upgrade to the versions to mitigate these security risks.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

GitHub has released security updates for Enterprise Server (GHES) addressing critical vulnerabilities, including CVE-2024-9487, which allows attackers to bypass SAML single sign-on authentication. This flaw permits unauthorized provisioning of users, potentially granting unauthorized access to the instance due to improper verification of cryptographic signatures. Additionally, an information disclosure vulnerability, CVE-2024-9539, has been identified, which could allow attackers to retrieve metadata from victim users through malicious SVG asset links. The vulnerability is related to a regression stemming from CVE-2024-4985, which was patched earlier, and is similar in severity to CVE-2024-6800, a critical flaw that could be exploited to gain site administrator privileges. Organizations operating vulnerable self-hosted versions of GHES are strongly encouraged to upgrade to the versions to mitigate these security risks.[emaillocker id="1283"]

 

  • CVE-2024-9487: It is a critical vulnerability in GitHub Enterprise Server that allows attackers to bypass SAML single sign-on (SSO) authentication due to improper verification of cryptographic signatures. This flaw enables unauthorized provisioning of users and access to the instance, posing a significant security risk. Organizations are urged to update patched versions to safeguard against potential exploitation.

 

  • CVE-2024-9539: It is an information disclosure vulnerability in GitHub Enterprise Server that allows attackers to retrieve metadata belonging to victim users. This occurs when malicious URLs for SVG assets are clicked, exposing sensitive user data. This vulnerability can lead to unauthorized access to sensitive user information.

 

  • CVE-2024-4985: It is a critical vulnerability in GitHub Enterprise Server (GHES) that allows attackers to bypass authentication and gain administrative privileges. It has a maximum severity on the scale and affects versions prior to specifically those using SAML single sign-on (SSO) with the optional encrypted assertions feature enabled.

 

  • CVE-2024-6800: It is a critical XML signature wrapping vulnerability in GitHub Enterprise Server (GHES). It affects systems using SAML authentication with specific identity providers, allowing an attacker with network access to forge SAML responses. This could result in unauthorized provisioning or site administrator access without prior authentication.

RECOMMENDATION:

  • We strongly recommend you update GitHub Enterprise Server to version 3.14.2, 3.13.5, 3.12.10 and 3.11.16.

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2024/10/github-patches-critical-flaw-in.html

[/emaillocker]
crossmenu