# GitHub Enterprise Server SAML encrypted-assertion bypass

Source: https://startwithidentity.com/cves/cve-2024-4985/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

GitHub Enterprise Server's optional encrypted-[SAML](https://startwithidentity.com/glossary/saml/) assertions feature did not bind the signature to the assertion it later consumed. An attacker who could reach the ACS forged a response and provisioned a site administrator, with no prior account. Reported through the GitHub Bug Bounty. Fixed in GHES 3.9.15, 3.10.12, 3.11.10, and 3.12.4 (May 2024). [CVE-2024-9487](https://startwithidentity.com/cves/cve-2024-9487/) is the incomplete-fix follow-on. [CVE-2024-6800](https://startwithidentity.com/cves/cve-2024-6800/) is a related wrapping path on the same product.

## Why it matters

Encrypted assertions are sold as the "more secure" SAML mode. Here they were the bypass. GHES is often the crown-jewel [service provider](https://startwithidentity.com/glossary/service-provider/) in an enterprise: source, Actions secrets, and deploy keys. An SSO forge there is a supply-chain incident, not a login ticket. The 2025 GHES canonicalization bug ([CVE-2025-23369](https://startwithidentity.com/cves/cve-2025-23369/)) is the same lesson a year later.

## What to do

- Confirm every GHES appliance is past the May 2024 builds, then take the [9487](https://startwithidentity.com/cves/cve-2024-9487/) and [6800](https://startwithidentity.com/cves/cve-2024-6800/) updates as well.
- If encrypted assertions were on while unpatched, review newly provisioned site admins and PATs.
- Prefer [OIDC](https://startwithidentity.com/glossary/oidc/) to GitHub where you can. XML encryption does not save a broken verifier.

## After you patch

A SAML bypass means the service provider accepted an assertion it should have rejected, so anyone who exploited it authenticated as a real user and left a normal-looking log line.

- **Revoke every session** issued by the affected service provider, then rotate its session signing keys. Patching stops new forgeries and does nothing about sessions already minted.
- **Audit administrative accounts and group memberships** for changes during the exposure window. Signing in as an administrator is the point of this class, and adding a second account is the standard persistence step.
- **Rotate the identity provider signing certificate** if the flaw involved signature validation, and confirm the service provider pins the expected certificate rather than trusting anything in the assertion.
- **Check your own implementation for the same class**: exact-match comparison on verification results, rejection of unexpected signature algorithms, and audience and recency checks on every assertion. See [SAML 2.0](https://startwithidentity.com/standards/saml-2-0/) and [SAML vs OIDC](https://startwithidentity.com/guides/fundamentals/saml-vs-oidc/).

## Sources

- [NVD: CVE-2024-4985](https://nvd.nist.gov/vuln/detail/CVE-2024-4985)
- GitHub GHES release notes / bug-bounty advisory, May 2024
