CRITICAL🇵🇱 Wersja polska

CVE-2020-27847

CVSS 9.8v3.1pub. 2021-05-28upd. 2024-11-21

A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects dex versions before 2.27.0.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Linuxfoundation Dex

    APP
    Linuxfoundation
    < 2.27.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-39222CRITICAL9.3PL ✓same product

Kradzież kodu autoryzacji OAuth w Dex (OpenID Connect) — dostęp do tokenów

CVE-2020-26290CRITICAL9.3PL ✓same product

Dex SAML connector — pominięcie weryfikacji podpisu XML (signature bypass)

CVE-2024-23656HIGH7.5same product

Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves ...

CVE-2026-53488CRITICAL9.4PL ✓same vendor

containerd CRI plugin: brak walidacji etykiet obrazu umożliwia RCE na hoście

CVE-2026-44477CRITICAL9.4PL ✓same vendor

CloudNativePG: eskalacja uprawnień do superużytkownika PostgreSQL przez metrics exporter