PT-2021-18384 · Pomerium · Pomerium

CVE-2021-29652

·

Published

2021-04-02

·

Updated

2024-08-21

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pomerium versions 0.10.0 through 0.13.3
Description The issue is related to an Open Redirect in the user sign-in/out process. Some API endpoints under /.pomerium/ do not verify parameters with pomerium signature, which could allow modifying parameters intended to be trusted to Pomerium. This mainly affects routes responsible for sign in/out but does not introduce an authentication bypass.
Recommendations For versions 0.10.0 through 0.13.3, update to version 0.13.4 to resolve the issue. As a temporary workaround, consider restricting access to API endpoints under /.pomerium/ until the issue is resolved. Avoid using unverified parameters in the affected API endpoints until the issue is resolved.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29652
GHSA-FV82-R8QV-CH4V
GO-2022-0827

Affected Products

Pomerium