Skip to content

authenticate: pomerium_signature is not verified in middleware

High
travisgroth published GHSA-fv82-r8qv-ch4v Mar 31, 2021

Package

github.com/pomerium/pomerium (Golang)

Affected versions

0.10.0-0.13.3

Patched versions

0.13.4

Description

Impact

Some API endpoints under /.pomerium/ do not verify parameters with pomerium_signature. This could allow modifying parameters intended to be trusted to Pomerium.

The issue mainly affects routes responsible for sign in/out, but does not introduce an authentication bypass.

Patches

Patched in v0.13.4

Workarounds

None

References

None

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2021-29652

Weaknesses

Credits