Skip to content

OIDC claims not updated from Identity Provider in Pomerium

Moderate
travisgroth published GHSA-j6wp-3859-vxfg Nov 5, 2021

Package

gomod pomerium (Go)

Affected versions

0.14.0-0.15.5

Patched versions

0.15.6

Description

Impact

Changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using allowed_idp_claims as part of policy. If using allowed_idp_claims and a user's claims are changed, Pomerium can make incorrect authorization decisions.

Patches

v0.15.6

Workarounds

  • Clear data on databroker service by clearing redis or restarting the in-memory databroker to force claims to be updated

References

#2724

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2021-41230

Weaknesses