PT-2021-18384 · Pomerium · Pomerium

Published

2021-04-02

·

Updated

2024-08-21

·

CVE-2021-29652

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pomerium versions 0.10.0 through 0.13.3
Description The issue is related to an Open Redirect in the user sign-in/out process. Some API endpoints under /.pomerium/ do not verify parameters with pomerium signature, which could allow modifying parameters intended to be trusted to Pomerium. This mainly affects routes responsible for sign in/out but does not introduce an authentication bypass.
Recommendations For versions 0.10.0 through 0.13.3, update to version 0.13.4 to resolve the issue. As a temporary workaround, consider restricting access to API endpoints under /.pomerium/ until the issue is resolved. Avoid using unverified parameters in the affected API endpoints until the issue is resolved.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2021-29652
GHSA-FV82-R8QV-CH4V
GO-2022-0827

Affected Products

Pomerium