{"id":1243,"date":"2024-05-23T22:48:39","date_gmt":"2024-05-23T20:48:39","guid":{"rendered":"https:\/\/techlance.ddns.net\/?p=1243"},"modified":"2024-05-23T22:49:41","modified_gmt":"2024-05-23T20:49:41","slug":"github-enterprise-server-alustassa-havaittiin-vakava-turvallisuuspuute-joka-liittyy-saml-yksittaiskirjautumiseen-sso","status":"publish","type":"post","link":"https:\/\/techlance.ddns.net\/en\/github-enterprise-server-alustassa-havaittiin-vakava-turvallisuuspuute-joka-liittyy-saml-yksittaiskirjautumiseen-sso\/","title":{"rendered":"GitHub Enterprise Server -alustassa havaittiin vakava turvallisuuspuute, joka liittyy SAML-yksitt\u00e4iskirjautumiseen (SSO)."},"content":{"rendered":"<p>GitHub Enterprise Server -alustassa havaittiin vakava turvallisuuspuute, joka liittyy SAML-yksitt\u00e4iskirjautumiseen (SSO). Puutteen tunniste on CVE-2024-4985 ja se on luokiteltu kriittiseksi. Haavoittuvuus koskee j\u00e4rjestelmi\u00e4, joissa on k\u00e4yt\u00f6ss\u00e4 valinnainen salattujen v\u00e4itt\u00e4mien (encrypted assertions) ominaisuus SAML-autentikoinnissa.<\/p>\n\n\n\n<p><strong>Haavoittuvuuden Kuvaus<\/strong><\/p>\n\n\n\n<p>Ongelma mahdollistaa hy\u00f6kk\u00e4\u00e4j\u00e4n v\u00e4\u00e4rent\u00e4\u00e4 SAML-vastauksen, mik\u00e4 voi johtaa k\u00e4ytt\u00e4j\u00e4n luomiseen j\u00e4rjestelm\u00e4\u00e4n tai p\u00e4\u00e4syn saamiseen olemassa olevalla k\u00e4ytt\u00e4j\u00e4tilill\u00e4, jolla on yll\u00e4pit\u00e4j\u00e4oikeudet. T\u00e4m\u00e4 voi tapahtua ilman, ett\u00e4 hy\u00f6kk\u00e4\u00e4j\u00e4 tarvitsee aiempaa autentikointia j\u00e4rjestelm\u00e4\u00e4n.<\/p>\n\n\n\n<p><strong>Kenen on syyt\u00e4 huolestua?<\/strong><\/p>\n\n\n\n<p>Haavoittuvuus koskee vain niit\u00e4 GitHub Enterprise Server -instansseja, jotka k\u00e4ytt\u00e4v\u00e4t SAML SSO -autentikointia yhdess\u00e4 salattujen v\u00e4itt\u00e4mien kanssa. Jos instanssissa ei k\u00e4ytet\u00e4 SAML SSO:ta tai k\u00e4ytet\u00e4\u00e4n sit\u00e4 ilman salattujen v\u00e4itt\u00e4mien ominaisuutta, haavoittuvuus ei vaikuta siihen. Salatut v\u00e4itt\u00e4m\u00e4t eiv\u00e4t ole oletusarvoisesti k\u00e4yt\u00f6ss\u00e4.<\/p>\n\n\n\n<p><strong>Korjaustoimenpiteet<\/strong><\/p>\n\n\n\n<p>GitHub on jo julkaissut korjauksen t\u00e4m\u00e4n turvallisuuspuutteen osalta. Korjaus on saatavilla GitHub Enterprise Serverin versioissa 3.9.15, 3.10.12, 3.11.10 ja 3.12.4. Kriittisyytens\u00e4 vuoksi on suositeltavaa, ett\u00e4 kaikki k\u00e4ytt\u00e4j\u00e4t, jotka k\u00e4ytt\u00e4v\u00e4t haavoittuvia versioita, p\u00e4ivitt\u00e4v\u00e4t alustansa mahdollisimman pian uusimpaan, korjattuun versioon.<\/p>\n\n\n\n<p><strong>Yhteenveto<\/strong><\/p>\n\n\n\n<p>T\u00e4m\u00e4 haavoittuvuus korostaa j\u00e4rjestelmien jatkuvan yll\u00e4pidon ja p\u00e4ivitysten t\u00e4rkeytt\u00e4. Vaikka salattuja v\u00e4itt\u00e4mi\u00e4 ei ole oletusarvoisesti k\u00e4yt\u00f6ss\u00e4, ne organisaatiot, jotka ovat ottaneet ominaisuuden k\u00e4ytt\u00f6\u00f6n, ovat alttiita merkitt\u00e4v\u00e4lle tietoturvariskille. On t\u00e4rke\u00e4\u00e4, ett\u00e4 kaikki j\u00e4rjestelm\u00e4t p\u00e4ivitet\u00e4\u00e4n s\u00e4\u00e4nn\u00f6llisesti ja turvallisuuspuutteet korjataan nopeasti niiden havaitsemisen j\u00e4lkeen.<\/p>\n\n\n\n<p><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.12\/admin\/release-notes#3.12.4\">https:\/\/docs.github.com\/en\/enterprise-server@3.12\/admin\/release-notes#3.12.4<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>GitHub Enterprise Server -alustassa havaittiin vakava turvallisuuspuute, joka liittyy SAML-yksitt\u00e4iskirjautumiseen (SSO). Puutteen tunniste on CVE-2024-4985 ja se on luokiteltu kriittiseksi. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[21,9],"tags":[22,15],"class_list":["post-1243","post","type-post","status-publish","format-standard","hentry","category-data-protection","category-security","tag-data-protection","tag-tietoturva"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/posts\/1243","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/comments?post=1243"}],"version-history":[{"count":0,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/posts\/1243\/revisions"}],"wp:attachment":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/media?parent=1243"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/categories?post=1243"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/tags?post=1243"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}