CVE-2024-4985: Critical severity GitHub Enterprise Server vulnerability
An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional encrypted assertions feature. This vulnerability allowed an attacker to forge a SAML response to provision and/or gain access to a user with site administrator privileges. Exploitation of this vulnerability would allow unauthorized access to the instance without requiring prior authentication. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.13.0 and was fixed in versions 3.9.15, 3.10.12, 3.11.10 and 3.12.4. This vulnerability was reported via the GitHub Bug Bounty program.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
github/github-enterprise-serverto a version that resolves this vulnerability.Fixed in 3.13.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4985?
CVE-2024-4985 is considered a high-severity vulnerability due to the potential for unauthorized access through authentication bypass.
How do I fix CVE-2024-4985?
To mitigate CVE-2024-4985, users should upgrade their GitHub Enterprise Server to the latest version beyond 3.13.0.
What software versions are affected by CVE-2024-4985?
CVE-2024-4985 affects GitHub Enterprise Server versions 3.9.15, 3.10.12, 3.11.10, and all versions up to 3.13.0.
What attack vector does CVE-2024-4985 exploit?
CVE-2024-4985 exploits an authentication bypass via forged SAML responses when using SAML single sign-on with encrypted assertions.
Is CVE-2024-4985 related to GitHub's authentication features?
Yes, CVE-2024-4985 is specifically related to vulnerabilities in the SAML single sign-on authentication feature of GitHub Enterprise Server.