S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Network Vulnerabilities·Updated Nov 26, 2024

CVE-2024-9487 Scanner

CVE-2024-9487 Scanner - Improper Authentication vulnerability in GitHub Enterprise

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-9487
9.5
CVSScritical
Exploitable remotely over the internet · no authentication required.

An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning of users and access to the instance. Exploitation required the encrypted assertions feature to be enabled, and the attacker would require direct network access as well as a signed SAML response or metadata document. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.15 and was fixed in versions 3.11.16, 3.12.10, 3.13.5, and 3.14.2. This vulnerability was reported via the GitHub Bug Bounty program.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Enterprise Serverby GitHub
3.11.0
enterprise_serverby github
3.11.0
Updated Aug 22, 2026View on NVD →
Detail

GitHub Enterprise is a self-hosted instance of GitHub, tailored to provide organizations with full control over their repositories, contributors, and the development workflow. Recognized for its robust security features, GitHub Enterprise is a critical tool for large organizations and teams focused on efficient source code management and collaborative development. It is often used by DevOps teams to streamline continuous integration and continuous deployment pipelines. GitHub Enterprise simplifies project management through GitHub Actions, allowing advanced customization of automated tasks. It also supports extensive third-party integrations, enabling a versatile development ecosystem. Organizations favor GitHub Enterprise for its ability to integrate with corporate authentication systems, which is essential for maintaining secure access control in enterprise environments.

An improper authentication vulnerability exists in GitHub Enterprise, particularly affecting SAML SSO authentication mechanisms. This vulnerability arises from inadequate verification processes during cryptographic signature checks, presenting an opportunity for attackers to bypass authentication protocols. It affects systems where the encrypted assertions feature is enabled, potentially leading to unauthorized provisioning of user accounts and access control breaches. The exploitation demands the attacker has direct network access along with a forged SAML response or metadata document. GitHub patched this vulnerability by hardening the signature verification process, enhancing security for organizations employing SAML for authentication. This vulnerability, highlighted through the GitHub Bug Bounty program, underscores the critical nature of rigorous access control checks in enterprise environments.

Technically, this vulnerability lies within the cryptographic signature verification of SAML responses in GitHub Enterprise. The flaw allows malicious actors to craft responses that bypass intended checks, leading to unauthorized access. Specifically, those exploiting it need access to a SAML response or metadata document, which they manipulate to deceive the server's authentication procedures. Vulnerable endpoints exist where the SAML SSO is active, targeting parameters like SAMLResponse and RelayState, among others. To trigger the vulnerability, attackers leverage arbitrary SAML assertions that, due to improper validation, grant unapproved access levels. Patches have been included in several releases by incorporating stricter checks and robust cryptographic validation mechanisms.

If exploited, this vulnerability can pose significant risks, resulting in unauthorized user access across GitHub Enterprise configurations. Such unauthorized access could allow attackers to take control of repository settings, modify source codes, and compromise private organizational data. Potential implications further include the manipulation of Continuous Integration/Continuous Deployment (CI/CD) processes, which might lead to breaches or sabotage of critical workflow functions. Unchecked, this raises severe concerns about intellectual property theft and the inadvertent authorization of malicious components. Addressing this vulnerability promptly is vital to ensuring the integrity and confidentiality of related systems. Organizations must prioritize implementing the patches to prevent the exploitation of this vulnerability.

REFERENCES

Solution Advice
  • Upgrade to a fixed version of GitHub Enterprise Server (3.11.16, 3.12.10, 3.13.5, 3.14.2, or later) as soon as possible to ensure the patch is applied.
  • Implement strict network access controls to limit exposure to the server, reducing the potential for unauthorized SAML response submissions.
  • Enable logging and monitoring for signature verification failures to detect and respond to potential bypass attempts promptly.
  • Regularly audit SAML configurations and ensure only trusted identity providers are permitted within your environment.
  • Educate development and security teams about proper cryptographic signature implementation to prevent future vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.