Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2854 | Pomerium is an identity-aware access proxy. In distributed service mode, Pomerium's Authenticate service exposes pprof debug and prometheus metrics handlers to untrusted traffic. This can leak potentially sensitive environmental information or lead to limited denial of service conditions. This issue is patched in version v0.17.1 Workarounds: Block access to `/debug` and `/metrics` paths on the authenticate service. This can be done with any L7 proxy, including Pomerium's own proxy service. |
Github GHSA |
GHSA-q98f-2x4p-prjr | Exposure of debug and metrics endpoints in Pomerium |
Wed, 23 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T18:42:56.245Z
Reserved: 2022-02-10T00:00:00.000Z
Link: CVE-2022-24797
Updated: 2024-08-03T04:20:50.531Z
Status : Modified
Published: 2022-03-31T23:15:08.247
Modified: 2024-11-21T06:51:07.110
Link: CVE-2022-24797
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA