Pomerium vulnerable to Incorrect Authorization with specially crafted requests
Package
Affected versions
>= 0.22.0, < 0.22.2
>= 0.21.0, < 0.21.4
>= 0.20.0, < 0.20.1
>= 0.19.0, < 0.19.2
>= 0.18.0, < 0.18.1
< 0.17.4
Patched versions
0.22.2
0.21.4
0.20.1
0.19.2
0.18.1
0.17.4
Description
Published to the GitHub Advisory Database
May 26, 2023
Reviewed
May 26, 2023
Published by the National Vulnerability Database
May 30, 2023
Last updated
Nov 4, 2023
Impact
With specially crafted requests, incorrect authorization decisions may be made by Pomerium.
Patches
We are releasing patch fixes to address this vulnerability going back to
v0.17.X
. Please upgrade to:For more information
If you have any questions or comments about this advisory:
References