May 23, 2024, 10:13 a.m. | Zeljka Zorz

Help Net Security www.helpnetsecurity.com

A critical, 10-out-of-10 vulnerability (CVE-2024-4985) allowing unrestricted access to vulnerable GitHub Enterprise Server (GHES) instances has been fixed by Microsoft-owned GitHub. Fortunately, there is a catch that may narrow down the pool of potential victims: instances are vulnerable to attack only if they use SAML single sign-on (SSO) authentication AND have the (optional) encrypted assertions feature enabled. About CVE-2024-4985 GitHub Enterprise Server is a software development platform that organizations host either on-premises or on a … More →


The post …

access attack auth authentication bug bypass catch critical cve cve-2024 cve-2024-4985 don't miss down enterprise fixes github github enterprise server hot stuff may microsoft saml server severity sign single single sign-on software development sso vulnerability vulnerable

Information Technology Specialist I: Windows Engineer

@ Los Angeles County Employees Retirement Association (LACERA) | Pasadena, California

Information Technology Specialist I, LACERA: Information Security Engineer

@ Los Angeles County Employees Retirement Association (LACERA) | Pasadena, CA

Sr Patching and Deploy Analyst

@ Gulfstream Aerospace | Savannah, GA, US

Network Engineer/Architect, Advisor

@ Peraton | Laurel, MD, United States

Product Marketing Director, Risk & Exposure Management

@ Forescout Technologies Inc. | United States

Vice President, Controls Design & Development-1

@ State Street | Quincy, Massachusetts