CVE-2024-23656
Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS 1.1. `cmd/dex/serve.go` line 425 seemingly sets TLS 1.2 as minimum version, but the whole `tlsConfig` is ignored after `TLS cert reloader` was introduced in v2.37.0.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.43%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS 1.1. `cmd/dex/serve.go` line 425 seemingly sets TLS 1.2 as minimum version, but the whole `tlsConfig` is ignored after `TLS cert reloader` was introduced in v2.37.0. Configured cipher suites are not respected either. This issue is fixed in Dex 2.38.0.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.43% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-326, CWE-757
- Affected
- linuxfoundation/dex
- Source
- security-advisories@github.com
References
- https://github.com/dexidp/dex/blob/70d7a2c7c1bb2646b1a540e49616cbc39622fb83/cmd/dex/serve.go#L425Product
- https://github.com/dexidp/dex/commit/5bbdb4420254ba73b9c4df4775fe7bdacf233b17Patch
- https://github.com/dexidp/dex/issues/2848Issue Tracking
- https://github.com/dexidp/dex/pull/2964Issue Tracking, Patch
- https://github.com/dexidp/dex/security/advisories/GHSA-gr79-9v6v-gc9rExploit
- https://github.com/dexidp/dex/blob/70d7a2c7c1bb2646b1a540e49616cbc39622fb83/cmd/dex/serve.go#L425Product
- https://github.com/dexidp/dex/commit/5bbdb4420254ba73b9c4df4775fe7bdacf233b17Patch
- https://github.com/dexidp/dex/issues/2848Issue Tracking
- https://github.com/dexidp/dex/pull/2964Issue Tracking, Patch
- https://github.com/dexidp/dex/security/advisories/GHSA-gr79-9v6v-gc9rExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.