Insecure TLS configuration in Dex



Published: 2024-01-30
Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2024-23656
CWE-ID CWE-16
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Dex
Server applications / Directory software, identity management

Vendor Dex IdP

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Configuration

EUVDB-ID: #VU85912

Risk: Medium

CVSSv3.1: 4.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-23656

CWE-ID: CWE-16 - Configuration

Exploit availability: No

Description

The issue may allow a remote attacker to bypass implemented security restrictions.

The issue exists due to the application discards TLSconfig and always serves TLS 1.0/1.1 along with insecure ciphers. A remote attacker can perform MitM attack and gain access to sensitive information.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Dex: 2.37.0

External links

http://github.com/dexidp/dex/security/advisories/GHSA-gr79-9v6v-gc9r
http://github.com/dexidp/dex/issues/2848
http://github.com/dexidp/dex/pull/2964
http://github.com/dexidp/dex/commit/5bbdb4420254ba73b9c4df4775fe7bdacf233b17
http://github.com/dexidp/dex/blob/70d7a2c7c1bb2646b1a540e49616cbc39622fb83/cmd/dex/serve.go#L425


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###