github dexidp/dex v2.4.1

latest releases: v2.39.1, v2.39.0, v2.38.0...
7 years ago

This is a security release of dex that addresses a vulnerability in the LDAP connector.

Issue: Dex does not protect against LDAP servers that allow unauthenticated binds (usually disabled by default), which means a user can login to dex without a password via LDAP.

Users of the LDAP connector should update to this release immediately if their LDAP servers supports unauthenticated bind.

Don't miss a new dex release

NewReleases is sending notifications on new releases.