DirectorySecurity Advisories
Sign In
Security Advisories

CGA-w29q-h459-6537

Published

Last updated

https://images.chainguard.dev/security/CGA-w29q-h459-6537
Package

kots

Latest Update
Not affected
Aliases
  • CVE-2020-26290
  • GHSA-m9hp-7r99-94h5

Severity

9.3

Critical

CVSS V3

Summary

Critical security issues in XML encoding in github.com/dexidp/dex

Description

Impact

The following vulnerabilities have been disclosed, which impact users leveraging the SAML connector:

Signature Validation Bypass (CVE-2020-15216): https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7

encoding/xml instabilities:

Patches

Immediately update to Dex v2.27.0.

Workarounds

There are no known workarounds.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images