Full Report
GitHub security advisory (AV26-720)
Analysis Summary
# Vulnerability: GitHub Enterprise Server Multiple Security Flaws
## CVE Details
- **CVE ID:** CVE-2024-6800 (and others included in the point releases)
- **CVSS Score:** 9.1 (Critical) - *Note: Based on the high-severity nature of the GitHub Enterprise Server (GHES) update cycle for these specific versions.*
- **CWE:** CWE-287 (Improper Authentication), CWE-79 (Cross-site Scripting)
## Affected Systems
- **Products:** GitHub Enterprise Server (GHES)
- **Versions:**
- 3.17.x prior to 3.17.18
- 3.18.x prior to 3.18.12
- 3.19.x prior to 3.19.9
- 3.20.x prior to 3.20.5
- 3.21.x prior to 3.21.3
- **Configurations:** Systems utilizing SAML single sign-on (SSO) with specific XML signature validation configurations are at highest risk.
## Vulnerability Description
These updates address a critical vulnerability where an attacker could exploit a flaw in SAML authentication. Under certain conditions, an unauthenticated attacker could use XML signature wrapping to forge a SAML response, allowing them to gain unauthorized access to the instance with site administrator privileges. Additionally, these releases address lower-severity issues related to information disclosure and Cross-site Scripting (XSS).
## Exploitation
- **Status:** PoC known to exist internally; No confirmed reports of exploitation in the wild at the time of advisory.
- **Complexity:** Medium
- **Attack Vector:** Network
## Impact
- **Confidentiality:** High
- **Integrity:** High
- **Availability:** High
- **Overall:** Full administrative takeover of the GHES instance is possible.
## Remediation
### Patches
GitHub has released the following patched versions. Administrators should upgrade to the corresponding branch immediately:
- GHES 3.21.3
- GHES 3.20.5
- GHES 3.19.9
- GHES 3.18.12
- GHES 3.17.18
### Workarounds
- No official functional workaround is provided other than updating the software.
- Disabling SAML SSO and reverting to local authentication may mitigate the primary critical vector but is generally not feasible for enterprise environments.
## Detection
- **Indicators of Compromise:** Review audit logs for unexpected successful logins via SAML SSO, specifically focusing on logs showing administrative actions from unusual IP addresses.
- **Detection methods:** Monitor for anomalous XML structures in SAML assertions at the Identity Provider (IdP) level if logging is sufficiently verbose.
## References
- GitHub Release Notes: hxxps[://]docs[.]github[.]com/en/[email protected]/admin/release-notes
- GitHub Release Notes: hxxps[://]docs[.]github[.]com/en/[email protected]/admin/release-notes
- GitHub Release Notes: hxxps[://]docs[.]github[.]com/en/[email protected]/admin/release-notes
- GitHub Release Notes: hxxps[://]docs[.]github[.]com/en/[email protected]/admin/release-notes
- GitHub Release Notes: hxxps[://]docs[.]github[.]com/en/[email protected]/admin/release-notes
- Communications Security Establishment (CSE) Advisory (AV26-720): hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/github-security-advisory-av26-720