Misc GitHub Critical Security Vulnerability 22 August 2024

  • Thread starter Thread starter impeeza
  • Start date Start date
  • Views Views 617
  • Replies Replies 0

impeeza

¡Kabito!
Member
Joined
Apr 5, 2011
Messages
10,646
Solutions
3
Reaction score
31,701
Trophies
6
Age
48
Location
At my chair.
XP
40,309
Country
Colombia
GitHub Critical Security Vulnerability 22 August 2024
Attention: Delivery Partners, Security Leads, GitHub Admins.


GitHub has released fixes to address a set of three security flaws impacting its Enterprise Server product, including one critical bug that could be abused to gain site administrator privileges.

A critical flaw tracked as CVE-2024-6800 with a CVSS score of 9.5 that could allow attackers to gain site administrator privileges by exploiting SAML single sign-on (SSO) with certain identity providers.

GitHub also addressed two medium-severity flaws:

- CVE-2024-7711, which could let attackers modify issue titles, assignees and labels in public repositories
- CVE-2024-6337, which could permit unauthorized access to issue contents in private repositories via a GitHub App.

Platform Affected:

Please view the table for detailed information about the affected and fixed versions on the ThreatCon Page.

Actions Required: Action by 6 September

- Upgrade to the fixed versions by 6 September if not sooner.
- Please update in line with your accounts change management processes and contractual arrangements.
 

Site & Scene News

Popular threads in this forum