QID 981058

QID 981058: Go (go) Security Update for github.com/pomerium/pomerium (GHSA-gjcg-vrxg-xmgv)

Envoy, which Pomerium is based on, can abnormally terminate if an H/2 GOAWAY and SETTINGS frame are received in the same IO event.

This can lead to a DoS in the presence of untrusted *upstream* servers.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    0.15.1 contains an upgraded envoy binary with this vulnerability patched.Workaround:
    If only trusted upstreams are configured, there is not substantial risk of this condition being triggered.
    Vendor References

    CVEs related to QID 981058

    Software Advisories
    Advisory ID Software Component Link
    GHSA-gjcg-vrxg-xmgv github.com/pomerium/pomerium URL Logo github.com/advisories/GHSA-gjcg-vrxg-xmgv