CVE-2021-41230

MEDIUM5.3EPSS 0.24%

OIDC claims not updated from Identity Provider in Pomerium

Published: 11/10/2021Modified: 3/13/2026

Description

### Impact Changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using [`allowed_idp_claims`](https://www.pomerium.com/reference/#allowed-idp-claims) as part of policy. If using `allowed_idp_claims` and a user's claims are changed, Pomerium can make incorrect authorization decisions. ### Patches v0.15.6 ### Workarounds - Clear data on `databroker` service by clearing redis or restarting the in-memory databroker to force claims to be updated ### References https://github.com/pomerium/pomerium/pull/2724 ### For more information If you have any questions or comments about this advisory: * Open an issue in [Pomerium](https://github.com/pomerium/pomerium) * Email us at [[email protected]](mailto:[email protected])

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

References (6)