Dex is vulnerable to Signature Validation Bypass (CVE-2020-15216) #2985
Labels
complexity:easy
Something that requires less than a day to fix
topic:authentication
Anything related to user authentication
topic:build
Anything related to building steps
topic:security
Security-related issues
Component:
'Dex', 'containers', 'addons'
What happened:
Please see this post for more: GHSA-m9hp-7r99-94h5
MetalK8s users implementing the Dex SAML connector could be impacted since they run a Dex version inferior to v2.27.0
What was expected:
Dex is expected to be secured and up to date.
Steps to reproduce
None
Resolution proposal (optional):
The text was updated successfully, but these errors were encountered: