CVE-2021-39206: Incorrect Authorization with specially crafted requests

Published Sep 9, 2021
·
Updated

Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, contains two authorization related vulnerabilities CVE-2021-32777 and CVE-2021-32779. This may lead to incorrect routing or authorization policy decisions. With specially crafted requests, incorrect authorization or routing decisions may be made by Pomerium. Pomerium v0.14.8 and v0.15.1 contain an upgraded envoy binary with these vulnerabilities patched. This issue can only be triggered when using path prefix based policy. Removing any such policies should provide mitigation.

Affected Software

6 affected components
Envoyproxy Envoy<1.16.5
Envoyproxy Envoy>=1.17.0<1.17.4
Envoyproxy Envoy>=1.18.0<1.18.4
Envoyproxy Envoy=1.19.0
Pomerium pomerium>=0.11.0<0.14.8
Pomerium pomerium=0.15.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Pomerium to a version that resolves this vulnerability.

    Fixed in v0.14.8
  2. Upgrade

    Upgrade Pomerium to a version that resolves this vulnerability.

    Fixed in v0.15.1
  3. Configuration

    As a mitigation for CVE-2021-32777 and CVE-2021-32779, remove/disable any authorization policies that use path prefix based policy, since the issue can only be triggered with path prefix based policy.

    Pomerium path prefix based policy = remove/disable policies that use path prefix based policy

Event History

Sep 9, 2021
CVE Published
via MITRE·10:10 PM
Data Sourced
via MITRE·10:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is CVE-2021-39206?

CVE-2021-39206 is a vulnerability in Pomerium, an open source identity-aware access proxy, that is caused by two authorization vulnerabilities in the underlying Envoy proxy (CVE-2021-32777 and CVE-2021-32779).

2

How does CVE-2021-39206 affect Envoy?

CVE-2021-39206 affects Envoy versions 1.16.5 up to and including 1.19.0, which are used by Pomerium. It may lead to incorrect routing or authorization policy decisions.

3

How does CVE-2021-39206 impact Pomerium?

CVE-2021-39206 impacts Pomerium versions 0.11.0 up to and including 0.15.0, as they rely on the affected Envoy versions. It may result in incorrect authorization due to specially crafted requests.

4

What is the severity of CVE-2021-39206?

CVE-2021-39206 has a severity score of 8.6 (high).

5

How can I fix CVE-2021-39206 in Pomerium?

To fix CVE-2021-39206 in Pomerium, you should update to a version that includes a patched version of Envoy (higher than 1.19.0) and has fixed the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203