Lucene search

K
osvGoogleOSV:GHSA-M9HP-7R99-94H5
HistoryDec 20, 2021 - 5:53 p.m.

Critical security issues in XML encoding in github.com/dexidp/dex

2021-12-2017:53:53
Google
osv.dev
16

0.004 Low

EPSS

Percentile

73.7%

Impact

The following vulnerabilities have been disclosed, which impact users leveraging the SAML connector:

Signature Validation Bypass (CVE-2020-15216): https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7

encoding/xml instabilities:

Patches

Immediately update to Dex v2.27.0.

Workarounds

There are no known workarounds.