Skip to content

v2.4.1

Compare
Choose a tag to compare
@rithujohn191 rithujohn191 released this 04 May 22:17
· 2419 commits to master since this release
v2.4.1

This is a security release of dex that addresses a vulnerability in the LDAP connector.

Issue: Dex does not protect against LDAP servers that allow unauthenticated binds (usually disabled by default), which means a user can login to dex without a password via LDAP.

Users of the LDAP connector should update to this release immediately if their LDAP servers supports unauthenticated bind.