VDB
CVE-2024-4985
CVE-2024-4985
PUBLISHED
In Microsoft GitHub Enterprise besteht eine Schwachstelle. Diese Schwachstelle besteht im SAML- Single Sign-On-Authentifizierungsprozess mit der optionalen Funktion „Encrypted Assertions“. Sie ermöglicht es, eine SAML-Antwort zu fälschen. Ein entfernter, anonymer Angreifer kann diese Schwachstelle ausnutzen, um Zugriff auf ein Benutzerkonto mit Site-Administratorrechten zu erlangen.
EPSS 0.81% · 74.5th percentile
Risk Scores
EPSS Score
0.81%
74.5th percentile
Timeline
- May 20, 2024 CVE Published
- May 21, 2024 EPSS Score
- Jun 15, 2024 EPSS Score
- Jul 8, 2024 EPSS Score
- Aug 1, 2024 CVE Updated
- Aug 25, 2024 EPSS Score
- Sep 17, 2024 EPSS Score
- Oct 5, 2024 Coalition ESS Score
- Oct 11, 2024 EPSS Score
- Nov 4, 2024 EPSS Score
- Dec 22, 2024 EPSS Score
- Jan 15, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1211.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1211 advisory
- https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.15 advisory
- https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.12 advisory
- https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.10 advisory
- https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.4 advisory