GHSA-fv82-r8qv-ch4v
Dashboard / Vulnerabilities / GHSA-fv82-r8qv-ch4v
GHSA-fv82-r8qv-ch4v
Summary: pomerium_signature is not verified in middleware in github.com/pomerium/pomerium
Details: ### Impact Some API endpoints under /.pomerium/ do not verify parameters with pomerium_signature. This could allow modifying parameters intended to be trusted to Pomerium. The issue mainly affects routes responsible for sign in/out, but does not introduce an authentication bypass. ### Specific Go Packages Affected github.com/pomerium/pomerium/authenticate ### Patches Patched in v0.13.4 ### For more information If you have any questions or comments about this advisory * Open an issue in [pomerium](http://github.com/pomerium/pomerium) * Email us at [[email protected]](mailto:[email protected])
References: https://github.com/pomerium/pomerium/security/advisories/GHSA-fv82-r8qv-ch4v, https://nvd.nist.gov/vuln/detail/CVE-2021-29652, https://github.com/pomerium/pomerium/pull/2048
Affected packages
Package
Name: github.com/pomerium/pomerium
Purl: pkg:golang/github.com/pomerium/pomerium
Affected ranges
Type: SEMVER
Events:
