• Advertise
  • Support Center
Saturday, July 12, 2025
  • Login
  • Register
INNOCENT MICHAEL
  • HOME
  • MAIN CATEGORY
    • BREAKING NEWSUPDATES
      • BROWSE
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
      • USA NEWS
        • Browse News
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
      • CANADA NEWS
        • Browse News
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
      • UK NEWS
        • Browse News
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
      • NIGERIA NEWS
        • Browser News
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
    • WATCHVIDEOS
    • AUDIOPODCAST
    • BULLETIN
    • BUSINESS NEWS
    • CYBERSECURITY
    • ENTERTAINMENT
      • NEWS
    • TECHNOLOGY
      • TECH NEWS
      • HOMELAB
    • REDCARPET CHRONICLE
    • POLITICSNEWS
      • BROWSE
      • POLITICS NEWS (CA)
      • POLITICS NEWS (USA)
      • POLITICS NEWS (UK)
    • SPORTS
      • SPORTS UPDATE
      • AEW
      • WWE
  • SHOP
    • Browse Shop
  • QUICK LINKS
    • OUR PLATFORMS
  • LEGAL HUB
    • Wikipedia
    • ABOUT US
    • OUR EDITORIAL PHILOSOPY
Live TV Indicator
WATCH ONLINE TV
No Result
View All Result
INNOCENT MICHAEL
  • HOME
  • MAIN CATEGORY
    • BREAKING NEWSUPDATES
      • BROWSE
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
      • USA NEWS
        • Browse News
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
      • CANADA NEWS
        • Browse News
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
      • UK NEWS
        • Browse News
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
      • NIGERIA NEWS
        • Browser News
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
    • WATCHVIDEOS
    • AUDIOPODCAST
    • BULLETIN
    • BUSINESS NEWS
    • CYBERSECURITY
    • ENTERTAINMENT
      • NEWS
    • TECHNOLOGY
      • TECH NEWS
      • HOMELAB
    • REDCARPET CHRONICLE
    • POLITICSNEWS
      • BROWSE
      • POLITICS NEWS (CA)
      • POLITICS NEWS (USA)
      • POLITICS NEWS (UK)
    • SPORTS
      • SPORTS UPDATE
      • AEW
      • WWE
  • SHOP
    • Browse Shop
  • QUICK LINKS
    • OUR PLATFORMS
  • LEGAL HUB
    • Wikipedia
    • ABOUT US
    • OUR EDITORIAL PHILOSOPY
  • Login
  • Register
No Result
View All Result
INNOCENT MICHAEL
Home Patches
GitHub Enterprise Server Patches Critical Vulnerability – CVE-2024-9487 (CVSS 9.5)

GitHub Enterprise Server Patches Critical Vulnerability – CVE-2024-9487 (CVSS 9.5)

in Patches, Technology
0
Share on FacebookShare On Whatsapp

GitHub has rolled out security updates to resolve two vulnerabilities in GitHub Enterprise Server, one of which poses a critical security threat by potentially allowing attackers to bypass authentication mechanisms and gain unauthorized access.

The most serious of these, CVE-2024-9487, has been given a CVSS score of 9.5, indicating a critical risk level. This flaw occurs within the platform’s SAML SSO (Single Sign-On) authentication system and stems from improper cryptographic signature verification. As a result, the vulnerability could allow attackers to bypass SAML SSO authentication, enabling the unauthorized provisioning of users and unauthorized access to the GitHub instance. However, exploitation requires several specific conditions to be met:

  1. The “encrypted assertions” feature must be active on the GitHub Enterprise Server.
  2. The attacker needs direct network access to the server.
  3. The attacker must possess a legitimate signed SAML response or metadata document.

Even though these requirements narrow the attack surface, organizations utilizing SAML SSO with encrypted assertions are strongly advised to update their GitHub Enterprise Server immediately.

The second vulnerability, rated as medium severity, involves malicious URLs embedded in SVG graphics. Exploiting this flaw could allow an attacker to extract information about a victim who clicks on the malicious link, potentially exposing sensitive metadata. The attacker can then use this data to create a fake phishing page. This attack method is more complex, requiring the attacker to first upload the malicious SVGs onto the server and then convince the victim to click the embedded link.

Both vulnerabilities impact all versions of GitHub Enterprise Server released before version 3.15. To address these issues, GitHub has published updates in the following versions:

  • 3.11.16
  • 3.12.10
  • 3.13.5
  • 3.14.2

GitHub urges all GitHub Enterprise Server users to update to one of these patched versions as soon as possible to mitigate potential security risks.

ShareSendTweetShareShare

Related Posts

WP Ghost Plugin Exploit Lets Hackers Run Code Remotely
Technology

WP Ghost Plugin Exploit Lets Hackers Run Code Remotely

March 21, 2025
36
Why You Should Be Cautious with Extension Cords
Tech

Why You Should Be Cautious with Extension Cords

January 14, 2025
31
Do You Know How to Master Google for Deep Research?
Tech

Do You Know How to Master Google for Deep Research?

January 13, 2025
26
Do You Know How to Make Your Windows PC Boot Faster?
Apps

Do You Know How to Make Your Windows PC Boot Faster?

January 12, 2025
22
Effortlessly Automate Windows Updates with PowerShell
Tech

Automate Windows Updates with PowerShell

January 12, 2025
21
create-a-featured-image-for-a-blog-post-about-chinas
Technology

China’s Proposed Export Restrictions Could Reshape Global Battery Supply Chains

January 10, 2025
2
Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
video
play-rounded-fill

Stay Updated

Subscribe to our newsletter and be the first to receive updates, tips, and exclusive offers straight to your inbox.

Haysuite Haysuite Haysuite
The UK’s phone theft crisis is a wake-up call for digital security
Hackers

The UK’s phone theft crisis is a wake-up call for digital security

April 19, 2025
36
7 Clever Ways to Reuse Your Old Windows 10 PC
Tech

7 Clever Ways to Reuse Your Old Windows 10 PC

April 19, 2025
25
8 Proven Ways to Clear Clipboard on Windows 11 Safely
Windows

8 Proven Ways to Clear Clipboard on Windows 11 Safely

April 18, 2025
18
What to Do When Ransomware Hits: Pay or Prepare?
Ransomware

What to Do When Ransomware Hits: Pay or Prepare?

April 18, 2025
14
Meta Resumes EU AI Training: Why Europe’s Data Matters
AI

Meta Resumes EU AI Training: Why Europe’s Data Matters

April 16, 2025
25

© 2024 Innocent Michael Network Inc..

  • Wikipedia
  • CRM
  • Submit Your Article
  • Support
  • Legal
Menu
  • Wikipedia
  • CRM
  • Submit Your Article
  • Support
  • Legal

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Facebook
Sign Up with Google
Sign Up with Linked In
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Login
  • Sign Up
Live TV Indicator
WATCH ONLINE TV
  • HOME
  • BROWSE
    • WATCH
    • AUDIO
    • BULLETIN
    • BUSINESS NEWS
    • CYBERSECURITY
    • TECHNOLOGY
      • TECH NEWS
      • HOMELAB
    • REDCARPET CHRONICLE
  • NEWS
    • GLOBAL NEWS
    • USA NEWS
    • CANADA NEWS
    • UK NEWS
    • NIGERIA NEWS
  • POLITICS
    • POLITICS NEWS (GLOBAL)
    • POLITICS NEWS (CA)
    • POLITICS NEWS (USA)
    • POLITICS NEWS (UK)
  • SPORTS NEWS
    • SPORTS NEWS (GLOBAL)
    • AEW NEWS
    • SOCCER NEWS
    • WWE NEWS
  • SHOP
  • QUICK LINKS
  • LEGAL HUB

Copyright © 2024 INNOCENT MICHAEL NETWORK INC.

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply