Envoy, which Pomerium is based on, contains two authorization related vulnerabilities:
#fragment
element, causing a mismatch in path-prefix based authorization decisions.With specially crafted requests, incorrect authorization or routing decisions may be made by Pomerium.
Pomerium v0.14.8 and v0.15.1 contain an upgraded envoy binary with these vulnerabilities patched.
envoy GSA CVE-2021-32777 envoy GSA CVE-2021-32779 envoy announcement
If you have any questions or comments about this advisory: * Open an issue in pomerium/pomerium * Email us at security@pomerium.com
{ "nvd_published_at": "2021-09-09T23:15:00Z", "github_reviewed_at": "2021-09-10T16:40:43Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-863" ] }