Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/pomerium/pomerium: GHSA-r7rh-jww5-5fjr #3179

Closed
GoVulnBot opened this issue Oct 2, 2024 · 1 comment
Assignees
Labels

Comments

@GoVulnBot
Copy link

Advisory GHSA-r7rh-jww5-5fjr references a vulnerability in the following Go modules:

Module
github.com/pomerium/pomerium

Description:

Impact

We've identified a vulnerability in the Pomerium databroker service API that may grant unintended access under specific conditions. This affects only certain Pomerium Zero and Pomerium Enterprise deployments.

Who is affected?

A Pomerium deployment is susceptible to this issue if all of the following conditions are met:

  • You have issued a service account access token using Pomerium Zero or Pomerium Enterprise.
  • The access token has an explicit expiration date in the future.
  • The core Pomerium databroker gRPC ...

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/pomerium/pomerium
      versions:
        - fixed: 0.27.1
      vulnerable_at: 0.27.0
summary: |-
    Pomerium service account access token may grant unintended access to databroker
    API in github.com/pomerium/pomerium
cves:
    - CVE-2024-47616
ghsas:
    - GHSA-r7rh-jww5-5fjr
references:
    - advisory: https://github.com/advisories/GHSA-r7rh-jww5-5fjr
    - advisory: https://github.com/pomerium/pomerium/security/advisories/GHSA-r7rh-jww5-5fjr
    - fix: https://github.com/pomerium/pomerium/commit/e018cf0fc0979d2abe25ff705db019feb7523444
    - web: https://github.com/pomerium/pomerium/releases/tag/v0.27.1
source:
    id: GHSA-r7rh-jww5-5fjr
    created: 2024-10-02T22:01:23.33743042Z
review_status: UNREVIEWED

@gopherbot
Copy link
Contributor

Change https://go.dev/cl/619135 mentions this issue: data/reports: add 15 reports

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants