VendorsLinux Foundationdexall versions
Vulnerabilities

Linux Foundation Linuxfoundation Dex

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2020-27847
A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects dex versions before 2.27.0.
Published 2021-05-28 · Modified
9.8EPSS 0.017
CVE-2020-26290
Critical security issues in XML encoding in Dex
Published 2020-12-28 · Modified
9.6EPSS 0.010
CVE-2022-39222
OAuth authorization code exposure in Dex
Published 2022-10-06 · Modified
9.3EPSS 0.013
CVE-2024-23656
Dex 2.37.0 is discarding TLSconfig and always serves deprecated TLS 1.0/1.1 and insecure ciphers
Published 2024-01-25 · Modified
7.5EPSS 0.004