OIDC claims not updated from Identity Provider in Pomerium
Package
Affected versions
>= 0.14.0, < 0.15.6
Patched versions
0.15.6
Description
Published by the National Vulnerability Database
Nov 5, 2021
Reviewed
Nov 8, 2021
Published to the GitHub Advisory Database
Nov 10, 2021
Last updated
Feb 15, 2023
Impact
Changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using
allowed_idp_claims
as part of policy. If usingallowed_idp_claims
and a user's claims are changed, Pomerium can make incorrect authorization decisions.Patches
v0.15.6
Workarounds
databroker
service by clearing redis or restarting the in-memory databroker to force claims to be updatedReferences
pomerium/pomerium#2724
For more information
If you have any questions or comments about this advisory:
References