-
-
Notifications
You must be signed in to change notification settings - Fork 18.1k
Closed
Labels
1.severity: securityIssues which raise a security issue, or PRs that fix oneIssues which raise a security issue, or PRs that fix one
Description
- CVE-2021-41230 CVSSv3=8.8 (nixos-unstable)
CVE details
CVE-2021-41230
Pomerium is an open source identity-aware access proxy. In affected versions changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using allowed_idp_claims as part of policy. If using allowed_idp_claims and a user's claims are changed, Pomerium can make incorrect authorization decisions. This issue has been resolved in v0.15.6. For users unable to upgrade clear data on databroker service by clearing redis or restarting the in-memory databroker to force claims to be updated.
Scanned versions: nixos-unstable: 942eb9a.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
1.severity: securityIssues which raise a security issue, or PRs that fix oneIssues which raise a security issue, or PRs that fix one