Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Pomerium/
  3. Pomerium Enterprise

Pomerium Enterprise

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 10 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Self-hosted Zero Trust access proxy for securing human, service, and AI agent access

by Pomerium · pomerium.com · source ↗

Known CVEs (10)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2024-47616 ↗MEDIUM 6.82024

    Pomerium is an identity and context-aware access proxy. The Pomerium databroker service is responsible for managing all persistent Pomerium application state. Requests to the databroker service API ar…

  • CVE-2024-39315 ↗MEDIUM 5.72024

    Pomerium is an identity and context-aware access proxy. Prior to version 0.26.1, the Pomerium user info page (at `/.pomerium`) unintentionally included serialized OAuth2 access and ID tokens from the …

  • CVE-2023-33189 ↗CRITICAL 10.02023

    Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisions may be made by Pomerium. This issue has been patched in versions 0.17.4, 0.18…

  • CVE-2022-24797 ↗MEDIUM 6.52022

    Pomerium is an identity-aware access proxy. In distributed service mode, Pomerium's Authenticate service exposes pprof debug and prometheus metrics handlers to untrusted traffic. This can leak potenti…

  • CVE-2021-41230 ↗MEDIUM 5.32021

    Pomerium is an open source identity-aware access proxy. In affected versions changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using `allowed_idp_cla…

  • CVE-2021-39206 ↗HIGH 8.62021

    Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, contains two authorization related vulnerabilities CVE-2021-32777 and CVE-2021-32779. This may lead to incorr…

  • CVE-2021-39204 ↗HIGH 7.52021

    Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with excessive complexity. This can lead to high CPU utilizat…

  • CVE-2021-39162 ↗HIGH 8.62021

    Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, can abnormally terminate if an H/2 GOAWAY and SETTINGS frame are received in the same IO event. This can lead…

  • CVE-2021-29652 ↗MEDIUM 6.12021

    Pomerium from version 0.10.0-0.13.3 has an Open Redirect in the user sign-in/out process

  • CVE-2021-29651 ↗MEDIUM 6.12021

    Pomerium before 0.13.4 has an Open Redirect (issue 1 of 2).

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Secure Access Service Edge (SASE/SSE) products

see all →
  • 1Password Device Trust · 1Password
  • AWS Verified Access · Amazon Web Services, Inc.
  • Absolute Core · Absolute
  • Absolute Resilient, AI-powered SSE · Absolute
  • Agilicus · Agilicus
  • Akamai Enterprise Application Access · Akamai
  • Akamai Secure Internet Access Enterprise · Akamai
  • Alibaba Cloud Secure Access Service Edge · Alibaba Cloud