File tree 1 file changed +21
-0
lines changed
1 file changed +21
-0
lines changed Original file line number Diff line number Diff line change
1
+ module : github.com/pomerium/pomerium
2
+ versions :
3
+ - fixed : v0.15.6
4
+ description : |
5
+ Pomerium is an open source identity-aware access proxy. Changes to the OIDC
6
+ claims of a user after initial login are not reflected in policy evaluation
7
+ when using allowed_idp_claims as part of policy. If using allowed_idp_claims
8
+ and a user's claims are changed, Pomerium can make incorrect authorization
9
+ decisions.
10
+
11
+ For users unable to upgrade clear data on databroker service by clearing
12
+ redis or restarting the in-memory databroker to force claims to be updated.
13
+ cves :
14
+ - CVE-2021-41230
15
+ symbols :
16
+ - Manager.onUpdateRecords
17
+ links :
18
+ pr : https://github.com/pomerium/pomerium/pull/2724
19
+ commit : https://github.com/pomerium/pomerium/commit/f20542c4bf2cc691e4c324f7ec79e02e46d95511
20
+ context :
21
+ - https://github.com/pomerium/pomerium/security/advisories/GHSA-j6wp-3859-vxfg
You can’t perform that action at this time.
0 commit comments