GitHub Enterprise Server: Immediate action required!
Upgrade to #GHES version 3.19.3 or later - this release patches #CVE-2026-3854
https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
GitHub Enterprise Server: Immediate action required!
Upgrade to #GHES version 3.19.3 or later - this release patches #CVE-2026-3854
https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
I am experimenting with adding Gitea support to GARM (Github Actions Runner Manager).
The current WiP branch is here: https://github.com/cloudbase/garm/pull/393
I like the idea of adding endpoints for Gitea, GHES and Github proper and using the same GARM instance to manage runners for repos across multiple forges.
I just published "Why Bitbucket Never Caught Up With GitHub: A Comprehensive Analysis".
You can check my friend link here:
https://medium.com/@carlspring/why-bitbucket-never-caught-up-with-github-a-comprehensive-analysis-a09616cc48e9?sk=8829b3c881c4e05a9aa5d59e172954d7
GitHub patches critical Security Flaws in
Enterprise Server.
GitHub has released fixes to address a set of three security flaws impacting its Enterprise Server product, including one critical bug that could be abused to gain site administrator privileges.
[CVE-2024-7711]
[CVE-2024-6337]
[CVE-2024-6800]
https://docs.github.com/en/enterprise-[email protected]/admin/release-notes
#github #ghes #it #security #flaw #admin #privileges #privacy #programming #engineering #tech #media #news
🚨 Critical vulnerability (CVE-2024-6800) found in GitHub Enterprise Server versions. Attackers could bypass authentication and gain admin privileges. GitHub has released patches for affected versions. Over 36,500 GHES instances exposed online, mostly in the US. Update ASAP to versions 3.13.3, 3.12.8, 3.11.14, or 3.10.16 for security.
#GitHubSecurity #CyberSecurity #SoftwareUpdate #GHES
Bleeping Computers: https://www.bleepingcomputer.com/news/security/github-enterprise-server-vulnerable-to-critical-auth-bypass-flaw/
GitHub Issues Patch for Critical Exploit in Enterprise Server
The vulnerability affects all #GHES versions before 3.13.0 and achieves the highest possible CVSS score of 10. Instances with SAML SSO authentication are at risk. #GitHub
https://securityboulevard.com/2024/05/github-issues-patch-for-critical-exploit-in-enterprise-server/
I’ve got some really cool work news!
I recently joined a brand new team that is focused on improving the way licensing works. This includes
Enterprise Cloud,
Enterprise Server,
Copilot for Business and
Advanced Security
Let me know if you have any licensing feedback or woes!