Skip to content

Incorrect Authorization with specially crafted requests

Critical
desimone published GHSA-pvrc-wvj2-f59p May 26, 2023

Package

Pomerium Core (Pomerium)

Affected versions

<=v0.22.1

Patched versions

v0.22.2, v0.21.4, v0.20.1, v0.19.2, v0.18.1, v0.17.4

Description

Impact

With specially crafted requests, incorrect authorization decisions may be made by Pomerium.

Patches

We are releasing patch fixes to address this vulnerability going back to v0.17.X. Please upgrade to:

  • v0.22.2
  • v0.21.4
  • v0.20.1
  • v0.19.2
  • v0.18.1
  • v0.17.4

For more information

If you have any questions or comments about this advisory:

Severity

Critical
10.0
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

CVE ID

CVE-2023-33189

Weaknesses

Credits