GHSA-j6wp-3859-vxfg
Dashboard / Vulnerabilities / GHSA-j6wp-3859-vxfg
GHSA-j6wp-3859-vxfg
Summary: OIDC claims not updated from Identity Provider in Pomerium
Details: ### Impact Changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using [`allowed_idp_claims`](https://www.pomerium.com/reference/#allowed-idp-claims) as part of policy. If using `allowed_idp_claims` and a user's claims are changed, Pomerium can make incorrect authorization decisions. ### Patches v0.15.6 ### Workarounds - Clear data on `databroker` service by clearing redis or restarting the in-memory databroker to force claims to be updated ### References https://github.com/pomerium/pomerium/pull/2724 ### For more information If you have any questions or comments about this advisory: * Open an issue in [Pomerium](https://github.com/pomerium/pomerium) * Email us at [[email protected]](mailto:[email protected])
References: https://github.com/pomerium/pomerium/security/advisories/GHSA-j6wp-3859-vxfg, https://nvd.nist.gov/vuln/detail/CVE-2021-41230, https://github.com/pomerium/pomerium/pull/2724, https://github.com/pomerium/pomerium/commit/f20542c4bf2cc691e4c324f7ec79e02e46d95511, https://github.com/pomerium/pomerium, https://pkg.go.dev/vuln/GO-2021-0258
Affected packages
Package
Name: github.com/pomerium/pomerium
Purl: pkg:golang/github.com/pomerium/pomerium
Affected ranges
Type: SEMVER
Events:
