CVE-2024-23656
- EPSS 0.13%
- Veröffentlicht 25.01.2024 20:15:41
- Zuletzt bearbeitet 21.11.2024 08:58:06
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS 1.1. `cmd/dex/serve.go` line 425 seemingly sets TLS 1.2 as minimum version, but the whole `tlsConfig` is...
CVE-2022-39222
- EPSS 1%
- Veröffentlicht 06.10.2022 18:16:09
- Zuletzt bearbeitet 21.11.2024 07:17:49
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public clients (and by extension, clients accepting tokens issued by those Dex instances) are affected by this vulnerability if they are ru...
CVE-2020-27847
- EPSS 0.36%
- Veröffentlicht 28.05.2021 11:15:07
- Zuletzt bearbeitet 21.11.2024 05:21:55
A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest threat from this vulnerability is to confidentiality,...
CVE-2020-26290
- EPSS 0.5%
- Veröffentlicht 28.12.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:19:46
Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulnerabilities which impacts users leveraging the SAML connector. The vulnerabilities enables potential signature bypass due to issues ...