DirectorySecurity Advisories
Sign In
Security Advisories

CGA-qjrf-w56f-p6hw

Published

Last updated

https://images.chainguard.dev/security/CGA-qjrf-w56f-p6hw
Package

kots

Latest Update
Not affected
Aliases
  • CVE-2020-27847
  • GHSA-2x32-jm95-2cpx

Severity

9.8

Critical

CVSS V3

Summary

Authentication Bypass in dex

Description

A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects dex versions before 2.27.0.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images