PT-2021-18383 · Pomerium · Pomerium

Travisgroth

·

Published

2021-04-02

·

Updated

2024-08-21

·

CVE-2021-29651

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pomerium versions prior to 0.13.4
Description The issue allows an outside attacker to get a signed login URL that, upon visiting it, will redirect a victim to the attacker’s site, creating an Open Redirect problem and potentially leading to JWT leakage. With a leaked JWT, the attacker can unveil the victim’s identity, such as their email address, by supplying the JWT to the authenticate service. Additionally, if an application integrating Pomerium only verifies the iss claim and not the aud claim, the attacker can access it as the victim.
Recommendations For versions prior to 0.13.4, update to Pomerium version 0.13.4 or later to resolve the issue. As a temporary workaround, consider restricting programmatic access on protected sites to minimize the risk of exploitation. Avoid using the pomerium redirect uri parameter in the affected API endpoint until the issue is resolved.

Fix

Information Disclosure

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2021-29651
GHSA-35VC-W93W-75C2
GO-2022-0783

Affected Products

Pomerium