Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-27847

Опубликовано: 15 дек. 2020
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects dex versions before 2.27.0.

A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Отчет

Red Hat Advanced Cluster Management for Kubernetes 2.1 packages the dexidp/dex library in observatorium-container for use in testing. In production, this library and its functionality are not used, and can not be reached by an attacker. Thus, the severity of this vulnerability has been downgraded for this product. A future update will remove this dependency.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/observatorium-rhel8Will not fix

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-228->CWE-290
https://bugzilla.redhat.com/show_bug.cgi?id=1907732dexidp/dex: authentication bypass in saml authentication

EPSS

Процентиль: 57%
0.00357
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects dex versions before 2.27.0.

CVSS3: 9.8
github
около 4 лет назад

Authentication Bypass in dex

EPSS

Процентиль: 57%
0.00357
Низкий

9.8 Critical

CVSS3