Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisions may be made by Pomerium. This issue has been patched in versions 0.17.4, 0.18.1, 0.19.2, 0.20.1, 0.21.4 and 0.22.2.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/pomerium/pomerium(Go) | 0.22.0 | 0.22.2 | N/A |
| github.com/pomerium/pomerium(Go) | 0.21.0 | 0.21.4 | N/A |
| github.com/pomerium/pomerium(Go) | 0.20.0 | 0.20.1 | N/A |
| github.com/pomerium/pomerium(Go) | 0.19.0 | 0.19.2 | N/A |
| github.com/pomerium/pomerium(Go) | 0.18.0 | 0.18.1 | N/A |
| github.com/pomerium/pomerium(Go) | 0 | 0.17.4 | N/A |
CVSS Metrics