PT-2023-24206 · Pomerium · Pomerium

Nonsleepr

·

Publicado

2023-05-26

·

Atualizado

2024-08-20

·

CVE-2023-33189

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pomerium versions prior to 0.17.4 Pomerium versions prior to 0.18.1 Pomerium versions prior to 0.19.2 Pomerium versions prior to 0.20.1 Pomerium versions prior to 0.21.4 Pomerium versions prior to 0.22.2
Description Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisions may be made by Pomerium.
Recommendations Upgrade to version 0.17.4 or later. Upgrade to version 0.18.1 or later. Upgrade to version 0.19.2 or later. Upgrade to version 0.20.1 or later. Upgrade to version 0.21.4 or later. Upgrade to version 0.22.2 or later.

Exploit

Correção

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-33189
GHSA-PVRC-WVJ2-F59P
GO-2023-1800

Produtos afetados

Pomerium