9.3
CVSS V3
Critical security issues in XML encoding in github.com/dexidp/dex
The following vulnerabilities have been disclosed, which impact users leveraging the SAML connector:
Signature Validation Bypass (CVE-2020-15216): https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7
encoding/xml
instabilities:
Immediately update to Dex v2.27.0.
There are no known workarounds.