CVE-2024-6800
Last modified
CVE-2024-6800 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed signed federation metadata XML. This vulnerability allowed an attacker with direct network access to GitHub Enterprise Server to forge a SAML response to provision and/or gain access to a user with site administrator privileges. EPSS estimates a 1.53% chance of exploitation in the next 30 days.
Description
An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed signed federation metadata XML. This vulnerability allowed an attacker with direct network access to GitHub Enterprise Server to forge a SAML response to provision and/or gain access to a user with site administrator privileges. Exploitation of this vulnerability would allow unauthorized access to the instance without requiring prior authentication. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versions 3.13.3, 3.12.8, 3.11.14, and 3.10.16. This vulnerability was reported via the GitHub Bug Bounty program.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:H/U:Red
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Github | Enterprise Server | >= 3.10.0, < 3.10.16 |
| Github | Enterprise Server | >= 3.11.0, < 3.11.14 |
| Github | Enterprise Server | >= 3.12.0, < 3.12.8 |
| Github | Enterprise Server | >= 3.13.0, < 3.13.3 |
References
- https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.16Release Notes, Vendor Advisory
- https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.14Release Notes, Vendor Advisory
- https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.8Release Notes, Vendor Advisory
- https://docs.github.com/en/enterprise-server@3.13/admin/release-notes#3.13.3Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-6800?
How severe is CVE-2024-6800?
How do I fix CVE-2024-6800?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-6794A deserialization of untrusted data vulnerability exists in …9.8
- CVE-2024-6795In Connex health portal released before8/30/2024, SQL inject…9.8
- CVE-2024-6796In Baxter Connex health portal released before 8/30/2024, an…9.1
- CVE-2024-6797The DL Robots.txt WordPress plugin through 1.2 does not sani…4.8
- CVE-2024-6798The DL Verification WordPress plugin through 1.2 does not sa…4.8
- CVE-2024-6799The YITH Essential Kit for WooCommerce #1 plugin for WordPre…4.3
- CVE-2024-6801A vulnerability, which was classified as critical, has been …9.8
- CVE-2024-6802A vulnerability, which was classified as critical, was found…9.8
- CVE-2024-6803A vulnerability has been found in itsourcecode Document Mana…9.8
- CVE-2024-6804The Jeg Elementor Kit plugin for WordPress is vulnerable to …5.4
- CVE-2024-6805The NI VeriStand Gateway is missing authorization checks whe…9.8
- CVE-2024-6806The NI VeriStand Gateway is missing authorization checks whe…9.8
Are you affected by CVE-2024-6800?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
