blob: 8f357f682645fbff93e290978a68bda651519153 [file] [log] [blame]
id: GO-2024-2965
modules:
- module: github.com/pomerium/pomerium
versions:
- fixed: 0.26.1
vulnerable_at: 0.26.0
summary: Pomerium exposed OAuth2 access and ID tokens in user info endpoint response in github.com/pomerium/pomerium
cves:
- CVE-2024-39315
ghsas:
- GHSA-rrqr-7w59-637v
references:
- advisory: https://github.com/pomerium/pomerium/security/advisories/GHSA-rrqr-7w59-637v
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-39315
- fix: https://github.com/pomerium/pomerium/commit/4c7c4320afb2ced70ba19b46de1ac4383f3daa48
source:
id: GHSA-rrqr-7w59-637v
created: 2024-07-26T12:37:28.168563-04:00
review_status: UNREVIEWED