MEDIUM 5.3 Go

OIDC claims not updated from Identity Provider in Pomerium

GHSA-j6wp-3859-vxfg · CVE-2021-41230 · GO-2021-0258

Published · Modified

Description

Impact

Changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using allowed_idp_claims as part of policy. If using allowed_idp_claims and a user's claims are changed, Pomerium can make incorrect authorization decisions.

Patches

v0.15.6

Workarounds

  • Clear data on databroker service by clearing redis or restarting the in-memory databroker to force claims to be updated

References

https://github.com/pomerium/pomerium/pull/2724

For more information

If you have any questions or comments about this advisory:

Ready to move

Start Securing

Free, no credit card | First findings in minutes