Junglewise Threat Intelligence

CVE-2024-23656: GO-2024-2476 - Dex discarding TLSconfig and always serves deprecated TLS 1.0/1.1 and insecure ciphers in github.com/dexidp/dex

CVE-2024-23656 · Severity: low · CVSS 3.1 · Published 2024-06-28

Technologies: github.com/dexidp/dex (Go). Vendors: Go.

Executive brief

Dex discarding TLSconfig and always serves deprecated TLS 1.0/1.1 and insecure ciphers in github.com/dexidp/dex

Affected products

  • Go github.com/dexidp/dex

Related threats