{"id":"GHSA-pvrc-wvj2-f59p","summary":"Pomerium vulnerable to Incorrect Authorization with specially crafted requests","details":"### Impact\n\nWith specially crafted requests, incorrect authorization decisions may be made by Pomerium.\n\n### Patches\n\nWe are releasing patch fixes to address this vulnerability going back to `v0.17.X`. Please upgrade to:\n\n- v0.22.2\n- v0.21.4\n- v0.20.1\n- v0.19.2\n- v0.18.1\n- v0.17.4\n\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n- Open an issue in [pomerium/pomerium](https://github.com/pomerium/pomerium/issues)\n- Email us at [security@pomerium.com](mailto:security@pomerium.com)\n","aliases":["CVE-2023-33189","GO-2023-1800"],"modified":"2026-09-10T03:49:53.753350053Z","published":"2023-05-26T22:00:39Z","database_specific":{"cwe_ids":["CWE-285"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-05-26T22:00:39Z","nvd_published_at":"2023-05-30T06:16:37Z"},"references":[{"type":"WEB","url":"https://github.com/pomerium/pomerium/security/advisories/GHSA-pvrc-wvj2-f59p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-33189"},{"type":"WEB","url":"https://github.com/pomerium/pomerium/commit/d315e683357a9b587ba9ef399a8813bcc52fdebb"},{"type":"PACKAGE","url":"https://github.com/pomerium/pomerium"},{"type":"WEB","url":"https://github.com/pomerium/pomerium/releases/tag/v0.17.4"},{"type":"WEB","url":"https://github.com/pomerium/pomerium/releases/tag/v0.18.1"},{"type":"WEB","url":"https://github.com/pomerium/pomerium/releases/tag/v0.19.2"},{"type":"WEB","url":"https://github.com/pomerium/pomerium/releases/tag/v0.20.1"},{"type":"WEB","url":"https://github.com/pomerium/pomerium/releases/tag/v0.21.4"},{"type":"WEB","url":"https://github.com/pomerium/pomerium/releases/tag/v0.22.2"}],"affected":[{"package":{"name":"github.com/pomerium/pomerium","ecosystem":"Go","purl":"pkg:golang/github.com/pomerium/pomerium"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.22.0"},{"fixed":"0.22.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-pvrc-wvj2-f59p/GHSA-pvrc-wvj2-f59p.json"}},{"package":{"name":"github.com/pomerium/pomerium","ecosystem":"Go","purl":"pkg:golang/github.com/pomerium/pomerium"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.21.0"},{"fixed":"0.21.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-pvrc-wvj2-f59p/GHSA-pvrc-wvj2-f59p.json"}},{"package":{"name":"github.com/pomerium/pomerium","ecosystem":"Go","purl":"pkg:golang/github.com/pomerium/pomerium"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.20.0"},{"fixed":"0.20.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-pvrc-wvj2-f59p/GHSA-pvrc-wvj2-f59p.json"}},{"package":{"name":"github.com/pomerium/pomerium","ecosystem":"Go","purl":"pkg:golang/github.com/pomerium/pomerium"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.19.0"},{"fixed":"0.19.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-pvrc-wvj2-f59p/GHSA-pvrc-wvj2-f59p.json"}},{"package":{"name":"github.com/pomerium/pomerium","ecosystem":"Go","purl":"pkg:golang/github.com/pomerium/pomerium"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.18.0"},{"fixed":"0.18.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-pvrc-wvj2-f59p/GHSA-pvrc-wvj2-f59p.json"}},{"package":{"name":"github.com/pomerium/pomerium","ecosystem":"Go","purl":"pkg:golang/github.com/pomerium/pomerium"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.17.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-pvrc-wvj2-f59p/GHSA-pvrc-wvj2-f59p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"}]}