You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We've identified a vulnerability in the Pomerium databroker service API that may grant unintended access under specific conditions. This affects only certain Pomerium Zero and Pomerium Enterprise deployments.
Who is affected?
A Pomerium deployment is susceptible to this issue if all of the following conditions are met:
You have issued a service account access token using Pomerium Zero or Pomerium Enterprise.
The access token has an explicit expiration date in the future.
Advisory GHSA-r7rh-jww5-5fjr references a vulnerability in the following Go modules:
Description:
Impact
We've identified a vulnerability in the Pomerium databroker service API that may grant unintended access under specific conditions. This affects only certain Pomerium Zero and Pomerium Enterprise deployments.
Who is affected?
A Pomerium deployment is susceptible to this issue if all of the following conditions are met:
References:
Cross references:
See doc/quickstart.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: