Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2x32-jm95-2cpx

Опубликовано: 20 дек. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Authentication Bypass in dex

A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects dex versions before 2.27.0.

Пакеты

Наименование

github.com/dexidp/dex

go
Затронутые версииВерсия исправления

< 2.27.0

2.27.0

EPSS

Процентиль: 57%
0.00357
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-228
CWE-290

Связанные уязвимости

CVSS3: 9.8
redhat
около 5 лет назад

A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects dex versions before 2.27.0.

CVSS3: 9.8
nvd
больше 4 лет назад

A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects dex versions before 2.27.0.

EPSS

Процентиль: 57%
0.00357
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-228
CWE-290