CVE-2021-29652: Medium severity stellarium vulnerability
Impact Some API endpoints under /.pomerium/ do not verify parameters with pomeriumsignature. This could allow modifying parameters intended to be trusted to Pomerium.
The issue mainly affects routes responsible for sign in/out, but does not introduce an authentication bypass.
Specific Go Packages Affected github.com/pomerium/pomerium/authenticate
Patches Patched in v0.13.4
For more information If you have any questions or comments about this advisory Open an issue in pomerium Email us at security@pomerium.com
Other sources
Pomerium from version 0.10.0-0.13.3 has an Open Redirect in the user sign-in/out process
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-29652.
What is the severity level of CVE-2021-29652?
The severity level of CVE-2021-29652 is medium with a CVSS score of 6.1.
Which software versions are affected by CVE-2021-29652?
Software versions between 0.10.0 and 0.13.3 of Pomerium and Pomerium package with version less than 0.13.4 are affected by CVE-2021-29652.
How does CVE-2021-29652 impact Pomerium?
CVE-2021-29652 allows modifying parameters intended to be trusted to Pomerium in certain API endpoints, mainly affecting routes responsible for sign in/out, but does not introduce an authentication bypass.
How can I fix the vulnerability CVE-2021-29652?
Upgrade your Pomerium and Pomerium package to version 0.13.4 or higher to fix the vulnerability CVE-2021-29652.