Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m9hp-7r99-94h5

Опубликовано: 20 дек. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.3

Описание

Critical security issues in XML encoding in github.com/dexidp/dex

Impact

The following vulnerabilities have been disclosed, which impact users leveraging the SAML connector:

Signature Validation Bypass (CVE-2020-15216): https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7

encoding/xml instabilities:

Patches

Immediately update to Dex v2.27.0.

Workarounds

There are no known workarounds.

Пакеты

Наименование

github.com/dexidp/dex

go
Затронутые версииВерсия исправления

< 2.27.0

2.27.0

Наименование

github.com/russellhaering/goxmldsig

go
Затронутые версииВерсия исправления

< 1.1.0

1.1.0

EPSS

Процентиль: 65%
0.005
Низкий

9.3 Critical

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 9.3
nvd
около 5 лет назад

Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulnerabilities which impacts users leveraging the SAML connector. The vulnerabilities enables potential signature bypass due to issues with XML encoding in the underlying Go library. The vulnerabilities have been addressed in version 2.27.0 by using the xml-roundtrip-validator from Mattermost (see related references).

CVSS3: 9.3
debian
около 5 лет назад

Dex is a federated OpenID Connect provider written in Go. In Dex befor ...

EPSS

Процентиль: 65%
0.005
Низкий

9.3 Critical

CVSS3

Дефекты

CWE-347