CVE-2021-29652Open Redirect in Pomerium Pomerium

CWE-601Open Redirect4 documents3 sources
Severity
6.1MEDIUMNVD
EPSS
0.2%
top 60.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 2
Latest updateAug 21

Description

Pomerium from version 0.10.0-0.13.3 has an Open Redirect in the user sign-in/out process

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

Gogithub.com/pomerium_pomerium0.10.00.13.4
NVDpomerium/pomerium0.10.00.13.3

🔴Vulnerability Details

3
OSV
pomerium_signature is not verified in middleware in github.com/pomerium/pomerium2024-08-21
OSV
pomerium_signature is not verified in middleware in github.com/pomerium/pomerium2021-05-21
GHSA
pomerium_signature is not verified in middleware in github.com/pomerium/pomerium2021-05-21
CVE-2021-29652 — Open Redirect in Pomerium Pomerium | cvebase