We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
In GitHub Security Advisory GHSA-pvrc-wvj2-f59p, there is a vulnerability in the following Go packages or modules:
Cross references:
See doc/triage.md for instructions on how to triage this report.
modules: - module: github.com/pomerium/pomerium versions: - fixed: 0.17.4 packages: - package: github.com/pomerium/pomerium - module: github.com/pomerium/pomerium versions: - introduced: 0.18.0 fixed: 0.18.1 packages: - package: github.com/pomerium/pomerium - module: github.com/pomerium/pomerium versions: - introduced: 0.19.0 fixed: 0.19.2 packages: - package: github.com/pomerium/pomerium - module: github.com/pomerium/pomerium versions: - introduced: 0.20.0 fixed: 0.20.1 packages: - package: github.com/pomerium/pomerium - module: github.com/pomerium/pomerium versions: - introduced: 0.21.0 fixed: 0.21.4 packages: - package: github.com/pomerium/pomerium - module: github.com/pomerium/pomerium versions: - introduced: 0.22.0 fixed: 0.22.2 packages: - package: github.com/pomerium/pomerium summary: Pomerium vulnerable to Incorrect Authorization with specially crafted requests description: | ### Impact With specially crafted requests, incorrect authorization decisions may be made by Pomerium. ### Patches We are releasing patch fixes to address this vulnerability going back to `v0.17.X`. Please upgrade to: - v0.22.2 - v0.21.4 - v0.20.1 - v0.19.2 - v0.18.1 - v0.17.4 ### For more information If you have any questions or comments about this advisory: - Open an issue in [pomerium/pomerium](https://github.com/pomerium/pomerium/issues) - Email us at [[email protected]](mailto:[email protected]) cves: - CVE-2023-33189 ghsas: - GHSA-pvrc-wvj2-f59p references: - advisory: https://github.com/pomerium/pomerium/security/advisories/GHSA-pvrc-wvj2-f59p - fix: https://github.com/pomerium/pomerium/commit/d315e683357a9b587ba9ef399a8813bcc52fdebb - advisory: https://github.com/advisories/GHSA-pvrc-wvj2-f59p
The text was updated successfully, but these errors were encountered:
Duplicate of #1800
Sorry, something went wrong.
tatianab
No branches or pull requests
In GitHub Security Advisory GHSA-pvrc-wvj2-f59p, there is a vulnerability in the following Go packages or modules:
Cross references:
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: