CVE-2024-47616
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Summary
CVE-2024-47616 is a vulnerability affecting Pomerium, an identity and context-aware access proxy. The issue lies with the Pomerium databroker service, which manages application state and is authorized based on JSON Web Tokens (JWTs). Incomplete JWT validation allows some service account access tokens to be incorrectly treated as valid, potentially granting unauthorized access to the databroker API. If exploited, this vulnerability could lead to user information exfiltration, session spoofing, or manipulation of Pomerium settings. This issue arises when a service account access token is issued using Pomerium Zero or Enterprise, has a future expiration date, and the core databroker API is not secured by network access controls. The vulnerability is resolved in version 0.27.1.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.