Cookie Consent by Free Privacy Policy Generator Aktuallisiere deine Cookie Einstellungen ๐Ÿ“Œ Critical SAML Exploit in GitHub Enterprise Server Fixed with Urgent Update


๐Ÿ“š Critical SAML Exploit in GitHub Enterprise Server Fixed with Urgent Update


๐Ÿ’ก Newskategorie: Hacking
๐Ÿ”— Quelle: blackhatethicalhacking.com

Critical SAML Exploit in GitHub Enterprise Server Fixed with Urgent Update




Join our Patreon Channel and Gain access to 70+ Exclusive Walkthrough Videos.

Patreon
Reading Time: 3 Minutes

GitHub Fixes Critical Authentication Bypass Vulnerability in Enterprise Server

GitHub has addressed a maximum severity vulnerability, tracked as CVE-2024-4985, which threatened GitHub Enterprise Server (GHES) instances using SAML single sign-on (SSO) authentication. This critical flaw carried a CVSS v4 score of 10.0, indicating its potential for severe impact.

Vulnerability Overview

The authentication bypass vulnerability allowed threat actors to forge a SAML response, thereby gaining administrator privileges without needing any authentication. This would grant attackers unrestricted access to all contents of a GHES instance.

GHES and Its Users

GitHub Enterprise Server is a self-hosted version of GitHub, tailored for organizations that require their repositories to be stored on their own servers or private cloud environments. It caters to large enterprises, development teams needing greater control, entities handling sensitive data, and users requiring offline access.

See Also: So, you want to be a hacker?
Offensive Security, Bug Bounty Courses




Discover your weakest link. Be proactive, not reactive. Cybercriminals need just one flaw to strike.

Specifics of the Flaw

The vulnerability affected instances utilizing SAML SSO with encrypted assertions, an optional security feature designed to protect data against interception. As this is not a default setting, only instances with this feature enabled were at risk.

โ€œOn instances that use SAML single sign-on (SSO) authentication with the optional encrypted assertions feature, an attacker could forge a SAML response to provision and/or gain access to a user with administrator privileges,โ€ GitHub explained.

Patches and Fixes

GitHub has released fixes in versions 3.12.4, 3.11.10, 3.10.12, and 3.9.15 of GitHub Enterprise Server, all made available on May 20. Administrators are urged to update to these versions immediately to secure their instances.




Known Issues Post-Update

While the updates address the critical vulnerability, they come with several known issues:

  • Custom firewall rules may be wiped.
  • Configuration validation may show โ€œNo such objectโ€ errors for Notebook and Viewscreen services, which can be ignored.
  • The Management Console root admin account may not unlock automatically after a lockout, requiring SSH access.
  • TLS-enabled log forwarding may fail due to CA bundle issues.
  • AWS instances might lose system time synchronization after a reboot.
  • All client IPs might appear as 127.0.0.1 in audit logs when using the X-Forwarded-For header behind a load balancer.
  • Large .adoc files may not render in the web UI but remain available as plaintext.
  • Backup restoration using ghe-restore may fail if Redis hasnโ€™t restarted properly.
  • Repositories imported using ghe-migrator may not track Advanced Security contributions correctly.
  • GitHub Actions workflows for GitHub Pages may fail, requiring specific SSH commands to fix (details provided in the bulletin).

Immediate Action Required

Despite the noted issues, it is crucial for users with the vulnerable configuration (SAML SSO with encrypted assertions) to update to the safe versions of GHES immediately. This proactive step is essential to mitigate the risk of exploitation and ensure the security of their systems.

Are u a security researcher? Or a company that writes articles about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing? If you want to express your idea in an article contact us here for a quote: [email protected]

Source: bleepingcomputer.com

Source Link

Merch

Offensive Security & Ethical Hacking Course

Begin the learning curve of hacking now!


Information Security Solutions

Find out how Pentesting Services can help you.


Join our Community

The post Critical SAML Exploit in GitHub Enterprise Server Fixed with Urgent Update first appeared on Black Hat Ethical Hacking. ...



๐Ÿ“Œ Critical SAML Exploit in GitHub Enterprise Server Fixed with Urgent Update


๐Ÿ“ˆ 69.09 Punkte

๐Ÿ“Œ Critical SAML Auth Bypass Vulnerability Found in GitHub Enterprise Server


๐Ÿ“ˆ 36.42 Punkte

๐Ÿ“Œ When it comes to patches, how urgent is urgent? [Chet Chat Podcast 268]


๐Ÿ“ˆ 32.22 Punkte

๐Ÿ“Œ KeyCloak prior 4.6.0.Final SAML Broker Endpoint SAML Assertion Replay weak authentication


๐Ÿ“ˆ 30.83 Punkte

๐Ÿ“Œ OmniAuth OmnitAuth-SAML up to 1.9.0 XML DOM SAML Data privilege escalation


๐Ÿ“ˆ 30.83 Punkte

๐Ÿ“Œ OneLogin Ruby-saml up to 1.6.0 XML DOM SAML Data privilege escalation


๐Ÿ“ˆ 30.83 Punkte

๐Ÿ“Œ miniOrange SAML SP Single Sign On plugin up to 4.8.72 on WordPress SAML Login Endpoint SAMLresponse cross site scripting


๐Ÿ“ˆ 30.83 Punkte

๐Ÿ“Œ KeyCloak 6.0.1 SAML Broker SAML Response privilege escalation


๐Ÿ“ˆ 30.83 Punkte

๐Ÿ“Œ pac4j-saml 3.x SAML Identifier Generator SAML2Utils.java RandomStringUtils PRNG weak authentication


๐Ÿ“ˆ 30.83 Punkte

๐Ÿ“Œ fusionauth-saml 0.2.3 Signature SAML Assertion improper authentication


๐Ÿ“ˆ 30.83 Punkte

๐Ÿ“Œ CVE-2015-5253 | Apache CXF up to 2.7.17/3.0.7/3.1.2 SAML Web SSO Module SAML Response access control (RHSA-2016:0321 / BID-77591)


๐Ÿ“ˆ 30.83 Punkte

๐Ÿ“Œ What is SAML and how SAML authentication works?


๐Ÿ“ˆ 30.83 Punkte

๐Ÿ“Œ CVE-2023-20264 | Cisco ASA/Firepower Threat Defense Software SAML permission (cisco-sa-asaftd-saml-hijack-ttuQfyz)


๐Ÿ“ˆ 30.83 Punkte

๐Ÿ“Œ New Silver SAML Attack Evades Golden SAML Defenses in Identity Systems


๐Ÿ“ˆ 30.83 Punkte

๐Ÿ“Œ New Silver SAML Attack Let Attackers Forge Any SAML Response To Entra ID


๐Ÿ“ˆ 30.83 Punkte

๐Ÿ“Œ Meet Silver SAML: Golden SAML in the Cloud - Eric Woodruff - BSW #348


๐Ÿ“ˆ 30.83 Punkte

๐Ÿ“Œ CVE-2024-1735 | armeria-saml up to 1.27.1 SAML Message improper authentication (GHSA-4m6j-23p2-8c54)


๐Ÿ“ˆ 30.83 Punkte

๐Ÿ“Œ GitHub warns of SAML auth bypass flaw in Enterprise Server


๐Ÿ“ˆ 30.35 Punkte

๐Ÿ“Œ JetBrains Urges Urgent Patching for Critical IntelliJ Vulnerability Exposing GitHub Tokens


๐Ÿ“ˆ 28.97 Punkte

๐Ÿ“Œ GitHub announces the preview of GitHub Copilot Enterprise and general availability of GitHub Copilot Chat


๐Ÿ“ˆ 25.44 Punkte

๐Ÿ“Œ #0daytoday #VxWorks 6.8 - TCP Urgent Pointer = 0 Integer Underflow Exploit [dos #exploits #0day #Exploit]


๐Ÿ“ˆ 25.23 Punkte

๐Ÿ“Œ Microsoft Releases Urgent Windows Update to Patch Two Critical Flaws


๐Ÿ“ˆ 24.44 Punkte

๐Ÿ“Œ Urgent: GitLab Releases Patch for Critical Vulnerabilities - Update ASAP


๐Ÿ“ˆ 24.44 Punkte

๐Ÿ“Œ Apple devices get urgent patch for zero-day exploit โ€“ update now!


๐Ÿ“ˆ 22.93 Punkte

๐Ÿ“Œ URGENT/11 VxWorks RTOS Vulnerabilities Found, Critical Systems Affected


๐Ÿ“ˆ 22.18 Punkte

๐Ÿ“Œ adobe has patched two critical flaws in acrobat and reader that warrant urgent attention.


๐Ÿ“ˆ 22.18 Punkte

๐Ÿ“Œ โ€˜URGENT/11โ€™ Critical Infrastructure Bugs Threaten EternalBlue-Style Attacks


๐Ÿ“ˆ 22.18 Punkte

๐Ÿ“Œ Urgent !! Windows User Urged to Patch A Critical Crypto Vulnerability on Windows 10, Clients & Servers Discovered By NSA


๐Ÿ“ˆ 22.18 Punkte

๐Ÿ“Œ Atlassian Ships Urgent Patch for Critical Bitbucket Vulnerability


๐Ÿ“ˆ 22.18 Punkte

๐Ÿ“Œ Microsoftโ€™s Urgent Fix: Bypassing Recent Patches for Critical Outlook Zero-Day Exploited in the Wild


๐Ÿ“ˆ 22.18 Punkte

๐Ÿ“Œ Critical Juniper Vulnerabilities Spark Urgent CISA Warning for Federal Agencies


๐Ÿ“ˆ 22.18 Punkte

๐Ÿ“Œ Urgent: VMware Warns of Unpatched Critical Cloud Director Vulnerability


๐Ÿ“ˆ 22.18 Punkte

๐Ÿ“Œ Microsoft Ships Urgent Fixes for Critical Flaws in Windows Kerberos, Hyper-V


๐Ÿ“ˆ 22.18 Punkte

๐Ÿ“Œ CISA Urges Critical Infrastructure to Patch Urgent ICS Vulnerabilities


๐Ÿ“ˆ 22.18 Punkte

๐Ÿ“Œ URGENT: Upgrade GitLab - Critical Workspace Creation Flaw Allows File Overwrite


๐Ÿ“ˆ 22.18 Punkte











matomo