OpenID Connect (OIDC) identity and OAuth 2.0 provider with pluggable connectors
github.com/dexidp/dex has critical vulnerabilities — do not use
Update to >= 2.35.0 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| critical | CVE-2020-27847 | Authentication Bypass in dex | 2.27.0 |
| high | CVE-2024-23656 | Dex discarding TLSconfig and always serves deprecated TLS 1.0/1.1 and insecure ciphers | 0.0.0-20240125115555-5bbdb4420254 |
| critical | CVE-2020-26290 | Critical security issues in XML encoding in github.com/dexidp/dex | 1.1.0 |
| critical | CVE-2022-39222 | Dex vulnerable to Man-in-the-Middle allowing ID token capture via intercepted authorization code | 2.35.0 |
| unknown | CVE-2024-23656 | Dex discarding TLSconfig and always serves deprecated TLS 1.0/1.1 and insecure ciphers in github.com/dexidp/dex | — |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/go/github.com/dexidp/dexLast updated · 2016-09-29T22:48:30Z