VDB
CVE-2020-26290
CVE-2020-26290
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulnerabilities which impacts users leveraging the SAML connector. The vulnerabilities enables potential signature bypass due to issues with XML encoding in the underlying Go library. The vulnerabilities have been addressed in version 2.27.0 by using the xml-roundtrip-validator from Mattermost (see related references).
EPSS 0.50% · 66.2th percentile
Risk Scores
CVSS v3.1
9.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
EPSS Score
0.50%
66.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| linuxfoundation | dex | 0 |
| github.com | dexidp/dex | 0 |
| dexidp | dex | < 2.27.0 |
| github.com | russellhaering/goxmldsig | 0 |
Timeline
- Dec 28, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 22, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 25, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 27, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 2, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://github.com/mattermost/xml-roundtrip-validator/blob/master/advisories/unstable-directives.md url
- https://github.com/mattermost/xml-roundtrip-validator/blob/master/advisories/unstable-elements.md url
- https://github.com/mattermost/xml-roundtrip-validator/blob/master/advisories/unstable-attributes.md url
- https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/ url
- https://github.com/dexidp/dex/security/advisories/GHSA-m9hp-7r99-94h5 url
- https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7 url
- https://github.com/dexidp/dex/commit/324b1c886b407594196113a3dbddebe38eecd4e8 url
- https://github.com/dexidp/dex/releases/tag/v2.27.0 url
- https://nvd.nist.gov/vuln/detail/CVE-2020-26290 advisory
- https://github.com/russellhaering/goxmldsig/commit/f6188febf0c29d7ffe26a0436212b19cb9615e64 url
- https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities url
- https://pkg.go.dev/vuln/GO-2020-0050 url