GO-2021-0258
Dashboard / Vulnerabilities / GO-2021-0258
GO-2021-0258
Summary: Incorrect authorization in github.com/pomerium/pomerium
Details: Pomerium is an open source identity-aware access proxy. Changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using allowed_idp_claims as part of policy. If using allowed_idp_claims and a user's claims are changed, Pomerium can make incorrect authorization decisions. For users unable to upgrade clear data on databroker service by clearing redis or restarting the in-memory databroker to force claims to be updated.
References: https://github.com/pomerium/pomerium/pull/2724, https://github.com/pomerium/pomerium/commit/f20542c4bf2cc691e4c324f7ec79e02e46d95511
Affected packages
Package
Name: github.com/pomerium/pomerium
Purl: pkg:golang/github.com/pomerium/pomerium
Affected ranges
Type: SEMVER
Events:
