GHSA-m9hp-7r99-94h5

Source
https://github.com/advisories/GHSA-m9hp-7r99-94h5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-m9hp-7r99-94h5/GHSA-m9hp-7r99-94h5.json
Aliases
Related
Published
2021-12-20T17:53:53Z
Modified
2023-11-10T21:41:30.893968Z
Details

Impact

The following vulnerabilities have been disclosed, which impact users leveraging the SAML connector:

Signature Validation Bypass (CVE-2020-15216): https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7

encoding/xml instabilities: - Element namespace prefix instability (CVE-2020-29511) - Attribute namespace prefix instability (CVE-2020-29509) - Directive comment instability (CVE-2020-29510)

Patches

Immediately update to Dex v2.27.0.

Workarounds

There are no known workarounds.

References

Affected packages

Go / github.com/dexidp/dex

Package

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Fixed
2.27.0

Go / github.com/russellhaering/goxmldsig

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.1.0