CVE-2022-24797Sensitive Information Exposure in Pomerium Pomerium

Severity
9.1CRITICALNVD
EPSS
0.5%
top 35.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31
Latest updateSep 6

Description

Pomerium is an identity-aware access proxy. In distributed service mode, Pomerium's Authenticate service exposes pprof debug and prometheus metrics handlers to untrusted traffic. This can leak potentially sensitive environmental information or lead to limited denial of service conditions. This issue is patched in version v0.17.1 Workarounds: Block access to `/debug` and `/metrics` paths on the authenticate service. This can be done with any L7 proxy, including Pomerium's own proxy service.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages3 packages

NVDpomerium/pomerium0.16.00.17.1
Gogithub.com/pomerium_pomerium0.16.00.17.1
CVEListV5pomerium/pomerium>= v0.16.0, < v0.17.1

Patches

🔴Vulnerability Details

3
OSV
Exposure of debug and metrics endpoints in Pomerium2024-09-06
GHSA
Exposure of debug and metrics endpoints in Pomerium2024-09-06
OSV
Exposure of Sensitive Information in Pomerium in github.com/pomerium/pomerium2024-08-21
CVE-2022-24797 — Sensitive Information Exposure | cvebase