| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-47616 | Pomerium's service account access token may grant unintended access to databroker API | pomerium | pomerium | Medium | 6.8 | 2024-10-02 21:10:24 | Deep Dive |
| CVE-2024-39315 | Pomerium exposed OAuth2 access and ID tokens in user info endpoint response | pomerium | pomerium | Medium | 5.7 | 2024-07-02 20:02:06 | Deep Dive |
| CVE-2023-33189 | Incorrect Authorization with specially crafted requests | pomerium | pomerium | Critical | 10.0 | 2023-05-30 05:39:45 | Deep Dive |
| CVE-2022-24797 | Exposure of Sensitive Information in Pomerium | pomerium | pomerium | Medium | 6.5 | 2022-03-31 22:40:12 | Deep Dive |
| CVE-2021-41230 | OIDC claims not updated from Identity Provider in Pomerium | pomerium | pomerium | Medium | 5.3 | 2021-11-05 22:40:12 | Deep Dive |
| CVE-2021-39206 | Incorrect Authorization with specially crafted requests | pomerium | pomerium | High | 8.6 | 2021-09-09 22:10:15 | Deep Dive |
| CVE-2021-39204 | Excessive CPU usage in Pomerium | pomerium | pomerium | High | 7.5 | 2021-09-09 22:10:09 | Deep Dive |
| CVE-2021-39162 | Incorrect handling of H2 GOAWAY + SETTINGS frames | pomerium | pomerium | High | 8.6 | 2021-09-09 22:05:11 | Deep Dive |