CVE-2021-29652Medium· 6.1▾ Sunlitpomerium_signature is not verified in middleware in github.com/pomerium/pomerium
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
Some API endpoints under /.pomerium/ do not verify parameters with pomerium_signature. This could allow modifying parameters intended to be trusted to Pomerium.
The issue mainly affects routes responsible for sign in/out, but does not introduce an authentication bypass.
github.com/pomerium/pomerium/authenticate
Patched in v0.13.4
If you have any questions or comments about this advisory
github.com/pomerium/pomerium >= 0.10.0, < 0.13.4Upgrade to a patched release:
github.com/pomerium/pomerium 0.13.4Connected by shared product, vendor, weakness, or advisory.