HIGH
Dex 2.37.0 is discarding TLSconfig and always serves deprecated TLS 1.0/1.1 and insecure ciphers
Published Jan 25, 2024
8.7
HIGHCVSS 4.0
EPSS 0.43%
Description
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS 1.1. `cmd/dex/serve.go` line 425 seemingly sets TLS 1.2 as minimum version, but the whole `tlsConfig` is ignored after `TLS cert reloader` was introduced in v2.37.0. Configured cipher suites are not respected either. This issue is fixed in Dex 2.38.0.
Affected products
-
Affected
- = 2.37.0
- 2.37.0
No data.
No Red Hat product state for this CVE.
github.com/dexidp/dex
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/dexidp/dex | 0 | not fixed |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-0360 Advisory
- https://github.com/advisories/GHSA-gr79-9v6v-gc9r Advisory
- https://github.com/dexidp/dex/blob/70d7a2c7c1bb2646b1a540e49616cbc39622fb83/cmd/dex/serve.go#L425 x_refsource_MISCProduct
- https://github.com/dexidp/dex/commit/5bbdb4420254ba73b9c4df4775fe7bdacf233b17 x_refsource_MISCPatch
- https://github.com/dexidp/dex/issues/2848 x_refsource_MISCIssue Tracking
- https://github.com/dexidp/dex/pull/2964 x_refsource_MISCIssue TrackingPatch
- https://github.com/dexidp/dex/security/advisories/GHSA-gr79-9v6v-gc9r x_refsource_CONFIRMExploit
- https://nvd.nist.gov/vuln/detail/CVE-2024-23656
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-0360 | Advisory | |
| https://github.com/advisories/GHSA-gr79-9v6v-gc9r | Advisory | |
| https://github.com/dexidp/dex/blob/70d7a2c7c1bb2646b1a540e49616cbc39622fb83/cmd/dex/serve.go#L425 | x_refsource_MISCProduct | |
| https://github.com/dexidp/dex/commit/5bbdb4420254ba73b9c4df4775fe7bdacf233b17 | x_refsource_MISCPatch | |
| https://github.com/dexidp/dex/issues/2848 | x_refsource_MISCIssue Tracking | |
| https://github.com/dexidp/dex/pull/2964 | x_refsource_MISCIssue TrackingPatch | |
| https://github.com/dexidp/dex/security/advisories/GHSA-gr79-9v6v-gc9r | x_refsource_CONFIRMExploit | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-23656 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jan 25, 2024
Updated Jun 3, 2025
Reserved Jan 19, 2024
Link CVE-2024-23656
CISA Vulnrichment
Updated Jun 3, 2025
Red Hat
No data
GitHub
Link GHSA-GR79-9V6V-GC9R