Dexidp Dex vulnerabilities
4 known vulnerabilities affecting dexidp/dex.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-23656HIGHCVSS 7.5v= 2.37.02024-01-25
CVE-2024-23656 [HIGH] CWE-326 CVE-2024-23656: Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS 1.1. `cmd/dex/serve.go` line 425 seemingly sets TLS 1.2 as minimum version, but the whole `tlsConfig` is ignored after `TLS cert reloader` was introduced in v2.37.0. Configured cipher suites are not respecte
cvelistv5nvd
CVE-2022-39222MEDIUMCVSS 6.5fixed in 2.35.02022-10-06
CVE-2022-39222 [MEDIUM] CWE-200 CVE-2022-39222: Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex inst
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public clients (and by extension, clients accepting tokens issued by those Dex instances) are affected by this vulnerability if they are running a version prior to 2.35.0. An attacker can exploit this vulnerability by making a victim naviga
cvelistv5nvd
CVE-2020-27847CRITICALCVSS 9.8vdex 2.27.02021-05-28
CVE-2020-27847 [CRITICAL] CWE-228 CVE-2020-27847: A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SA
A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects dex versions before 2.27.0.
cvelistv5nvd
CVE-2020-26290CRITICALCVSS 9.6fixed in 2.27.02020-12-28
CVE-2020-26290 [CRITICAL] CWE-347 CVE-2020-26290: Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a cr
Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulnerabilities which impacts users leveraging the SAML connector. The vulnerabilities enables potential signature bypass due to issues with XML encoding in the underlying Go library. The vulnerabilities have been addressed in version
cvelistv5nvd