CVE-2024-9487: An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed when the encrypted assertions feature was enabled
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning of users and access to the instance. Exploitation required the encrypted assertions feature to be enabled, and the attacker would require direct network access as well as a signed SAML response or metadata document. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.15 and was fixed in versions 3.11.16, 3.12.10, 3.13.5, and 3.14.2. This vulnerability was reported via the GitHub Bug Bounty program.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9487?
CVE-2024-9487 is classified as a high severity vulnerability due to its potential to bypass SAML SSO authentication.
How do I fix CVE-2024-9487?
To fix CVE-2024-9487, upgrade GitHub Enterprise Server to a version higher than 3.11.16, 3.12.10, 3.13.5, or 3.14.2, depending on your current version.
What type of vulnerability is CVE-2024-9487?
CVE-2024-9487 is an improper verification of cryptographic signature vulnerability.
What are the impacts of CVE-2024-9487?
The exploitation of CVE-2024-9487 could result in unauthorized provisioning of users and access to the GitHub Enterprise Server instance.
Which versions of GitHub Enterprise Server are affected by CVE-2024-9487?
CVE-2024-9487 affects GitHub Enterprise Server versions prior to 3.11.16, 3.12.10, 3.13.5, and 3.14.2.