Web Hack List

Collected research

GitHub Enterprise SAML Authentication Bypass

GitHub Enterprise SAML Authentication Bypass (CVE-2024-4985 / CVE-2024-9487) — ProjectDiscovery Blog

Explains GitHub Enterprise SAML authentication failures caused by differences between the assertions validated for signatures and those consumed after decryption. Reconstructs the vulnerable processing order and a subsequent bypass, with disclosure context acknowledging an earlier private report.

Record

Document
GitHub Enterprise SAML Authentication Bypass (CVE-2024-4985 / CVE-2024-9487) — ProjectDiscovery Blog
Researcher
Harsh Jaiswal and Rahul Maini
Published by
ProjectDiscovery
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Harsh Jaiswal and Rahul Maini, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .