Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-228
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-38443 1 Eclipse 1 Cyclonedds 2022-05-12 7.5 HIGH 9.8 CRITICAL
Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.
CVE-2020-27847 1 Linuxfoundation 1 Dex 2021-06-02 7.5 HIGH 9.8 CRITICAL
A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects dex versions before 2.27.0.