- Joined
- Apr 5, 2011
- Messages
- 10,646
- Solutions
- 3
- Reaction score
- 31,701
- Trophies
- 6
- Age
- 48
- Location
- At my chair.
- XP
- 40,309
- Country

GitHub Critical Security Vulnerability 22 August 2024
Attention: Delivery Partners, Security Leads, GitHub Admins.
GitHub has released fixes to address a set of three security flaws impacting its Enterprise Server product, including one critical bug that could be abused to gain site administrator privileges.
A critical flaw tracked as CVE-2024-6800 with a CVSS score of 9.5 that could allow attackers to gain site administrator privileges by exploiting SAML single sign-on (SSO) with certain identity providers.
GitHub also addressed two medium-severity flaws:
- CVE-2024-7711, which could let attackers modify issue titles, assignees and labels in public repositories
- CVE-2024-6337, which could permit unauthorized access to issue contents in private repositories via a GitHub App.
Platform Affected:
Please view the table for detailed information about the affected and fixed versions on the ThreatCon Page.
Actions Required: Action by 6 September
- Upgrade to the fixed versions by 6 September if not sooner.
- Please update in line with your accounts change management processes and contractual arrangements.
Attention: Delivery Partners, Security Leads, GitHub Admins.
GitHub has released fixes to address a set of three security flaws impacting its Enterprise Server product, including one critical bug that could be abused to gain site administrator privileges.
A critical flaw tracked as CVE-2024-6800 with a CVSS score of 9.5 that could allow attackers to gain site administrator privileges by exploiting SAML single sign-on (SSO) with certain identity providers.
GitHub also addressed two medium-severity flaws:
- CVE-2024-7711, which could let attackers modify issue titles, assignees and labels in public repositories
- CVE-2024-6337, which could permit unauthorized access to issue contents in private repositories via a GitHub App.
Platform Affected:
Please view the table for detailed information about the affected and fixed versions on the ThreatCon Page.
Actions Required: Action by 6 September
- Upgrade to the fixed versions by 6 September if not sooner.
- Please update in line with your accounts change management processes and contractual arrangements.





