GitHub Enterprise Server
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*
- < 3.12.14
- < 3.13.10
- < 3.14.7
- < 3.15.2
- < 3.16.0
A vulnerability allowing signature spoofing has been identified in GitHub Enterprise Server. This issue arises from improper verification of cryptographic signatures in SAML responses, which could be exploited by unauthorized internal users to gain access to accounts with administrator privileges. The vulnerability affects all versions of GitHub Enterprise Server prior to 3.12.14, 3.13.10, 3.14.7, 3.15.2, and 3.16.0. Instances not using SAML single sign-on or where the attacker is not an existing user are not impacted.
Exploitation of this vulnerability could lead to unauthorized access and privileges on the affected GitHub Enterprise Server instance, allowing an attacker to impersonate an administrator.
To reproduce this vulnerability, an attacker must be an internal user on a GitHub Enterprise Server instance that uses SAML single sign-on with encrypted assertions. The attacker can forge a SAML response to gain access to an administrator account, taking advantage of the improper signature validation. This exploitation can be performed through the GitHub API or by manipulating SAML assertions via an identity provider that supports such actions.
Users can upgrade to GitHub Enterprise Server versions 3.12.14, 3.13.10, 3.14.7, or 3.15.2. For instructions on upgrading, see the GitHub Enterprise Server release notes.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.