Pomerium

Pomerium

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 02.10.2024 22:15:03
  • Zuletzt bearbeitet 04.10.2024 13:50:43

Pomerium is an identity and context-aware access proxy. The Pomerium databroker service is responsible for managing all persistent Pomerium application state. Requests to the databroker service API are authorized by the presence of a JSON Web Token (...

  • EPSS 0.32%
  • Veröffentlicht 02.07.2024 20:15:06
  • Zuletzt bearbeitet 11.04.2025 14:47:52

Pomerium is an identity and context-aware access proxy. Prior to version 0.26.1, the Pomerium user info page (at `/.pomerium`) unintentionally included serialized OAuth2 access and ID tokens from the logged-in user's session. These tokens are not int...

  • EPSS 0.2%
  • Veröffentlicht 30.05.2023 06:16:37
  • Zuletzt bearbeitet 21.11.2024 08:05:05

Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisions may be made by Pomerium. This issue has been patched in versions 0.17.4, 0.18.1, 0.19.2, 0.20.1, 0.21.4 and 0.22.2.

  • EPSS 0.47%
  • Veröffentlicht 31.03.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:07

Pomerium is an identity-aware access proxy. In distributed service mode, Pomerium's Authenticate service exposes pprof debug and prometheus metrics handlers to untrusted traffic. This can leak potentially sensitive environmental information or lead t...

  • EPSS 0.24%
  • Veröffentlicht 05.11.2021 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:25:50

Pomerium is an open source identity-aware access proxy. In affected versions changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using `allowed_idp_claims` as part of policy. If using `allowed_idp_clai...

  • EPSS 0.16%
  • Veröffentlicht 09.09.2021 23:15:13
  • Zuletzt bearbeitet 21.11.2024 06:18:53

Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, contains two authorization related vulnerabilities CVE-2021-32777 and CVE-2021-32779. This may lead to incorrect routing or authorization policy decisions. Wit...

  • EPSS 0.67%
  • Veröffentlicht 09.09.2021 22:15:09
  • Zuletzt bearbeitet 21.11.2024 06:18:45

Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, can abnormally terminate if an H/2 GOAWAY and SETTINGS frame are received in the same IO event. This can lead to a DoS in the presence of untrusted *upstream* ...

  • EPSS 0.41%
  • Veröffentlicht 09.09.2021 22:15:09
  • Zuletzt bearbeitet 21.11.2024 06:18:53

Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with excessive complexity. This can lead to high CPU utilization when a large number of streams are reset. This...

  • EPSS 0.2%
  • Veröffentlicht 02.04.2021 14:15:13
  • Zuletzt bearbeitet 21.11.2024 06:01:34

Pomerium before 0.13.4 has an Open Redirect (issue 1 of 2).

  • EPSS 0.18%
  • Veröffentlicht 02.04.2021 14:15:13
  • Zuletzt bearbeitet 21.11.2024 06:01:34

Pomerium from version 0.10.0-0.13.3 has an Open Redirect in the user sign-in/out process