A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects dex versions before 2.27.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLinuxfoundation Dex
APPLinuxfoundation< 2.27.0
Related vulnerabilities
Kradzież kodu autoryzacji OAuth w Dex (OpenID Connect) — dostęp do tokenów
Dex SAML connector — pominięcie weryfikacji podpisu XML (signature bypass)
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves ...
containerd CRI plugin: brak walidacji etykiet obrazu umożliwia RCE na hoście
CloudNativePG: eskalacja uprawnień do superużytkownika PostgreSQL przez metrics exporter