Executive brief
Critical security issues in XML encoding in github.com/dexidp/dex
Affected products
- Go github.com/russellhaering/goxmldsig
- Go github.com/dexidp/dex
CVE identifiers
- CVE-2020-26290
- CVE-2020-27847
Junglewise Threat Intelligence
CVE-2020-26290 · Severity: low · CVSS 3.1 · Published 2021-12-20
Technologies: github.com/russellhaering/goxmldsig (Go), github.com/dexidp/dex (Go). Vendors: Go.
Critical security issues in XML encoding in github.com/dexidp/dex