Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dex is vulnerable to Signature Validation Bypass (CVE-2020-15216) #2985

Closed
Ebaneck opened this issue Dec 15, 2020 · 1 comment · Fixed by #2990
Closed

Dex is vulnerable to Signature Validation Bypass (CVE-2020-15216) #2985

Ebaneck opened this issue Dec 15, 2020 · 1 comment · Fixed by #2990
Assignees
Labels
complexity:easy Something that requires less than a day to fix topic:authentication Anything related to user authentication topic:build Anything related to building steps topic:security Security-related issues

Comments

@Ebaneck
Copy link
Contributor

Ebaneck commented Dec 15, 2020

Component:

'Dex', 'containers', 'addons'

What happened:

Please see this post for more: GHSA-m9hp-7r99-94h5
MetalK8s users implementing the Dex SAML connector could be impacted since they run a Dex version inferior to v2.27.0

What was expected:

Dex is expected to be secured and up to date.

Steps to reproduce

None

Resolution proposal (optional):

  • Bump Dex version to v2.27.0.
@NicolasT
Copy link
Contributor

Important to note this only affects the SAML connector of Dex, which we're not using in the Scality products: any integration of the product with a SAML IdP would go through another user management system, to which Dex connects through OIDC.

However, indeed upgrading is the right action 👍

TeddyAndrieux added a commit that referenced this issue Dec 18, 2020
Because of "CVE-2020-15216" we need to use a newer Dex image, note that
at this time no stable repo exists for Dex helm3 chart so we still use
the deprected chart where we only bump the Dex image version

Fixes: #2985
@TeddyAndrieux TeddyAndrieux added complexity:easy Something that requires less than a day to fix topic:authentication Anything related to user authentication topic:security Security-related issues topic:build Anything related to building steps labels Dec 18, 2020
TeddyAndrieux added a commit that referenced this issue Dec 18, 2020
Because of "CVE-2020-15216" we need to use a newer Dex image, note that
at this time no stable repo exists for Dex helm3 chart so we still use
the deprecated chart where we only bump the Dex image version

Fixes: #2985
TeddyAndrieux added a commit that referenced this issue Dec 18, 2020
Because of "CVE-2020-15216" we need to use a newer Dex image, note that
at this time no stable repo exists for Dex helm3 chart so we still use
the deprecated chart where we only bump the Dex image version

Fixes: #2985
TeddyAndrieux added a commit that referenced this issue Dec 18, 2020
Because of "CVE-2020-15216" we need to use a newer Dex image, note that
at this time no stable repo exists for Dex helm3 chart so we still use
the deprecated chart where we only bump the Dex image version

Fixes: #2985
@bert-e bert-e closed this as completed in cbe37cd Dec 18, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
complexity:easy Something that requires less than a day to fix topic:authentication Anything related to user authentication topic:build Anything related to building steps topic:security Security-related issues
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants