Featured Stories

GitHub Enterprise SAML Authentication Bypass (CVE-2024-4985 / CVE-2024-9487)

GitHub Enterprise SAML Authentication Bypass (CVE-2024-4985 / CVE-2024-9487)

Introduction In light of the recent Ruby-SAML bypass discovered in GitLab, we set out to examine the SAML implementation within GitHub Enterprise. During our research, we identified a significant vulnerability that enabled bypassing GitHub’s SAML authentication when encrypted assertions were in use. This blog post will provide an in-depth look at GitHub Enterprise’s SAML implementation and analyze the specific code issue that permitted this bypass. Although we uncovered this vulnerability inde

Vulnerability Research Stories

Nuclei & Nuclei Template Stories

Vulnerability Management Stories

Educational Stories