Skip to content

Commit ce33151

Browse files
backport-actions-token[bot]kenjenkinsZPain8464
authored
changelog: add link to security advisory for v0.27.1 (#1633)
changelog: add link to security advisory for v0.27.1 (#1631) Co-authored-by: Kenneth Jenkins <[email protected]> Co-authored-by: zachary painter <[email protected]>
1 parent cecaeb0 commit ce33151

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

content/docs/core/changelog.mdx

+2
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,8 @@ Please refer to the [upgrade guide](/docs/core/upgrading) before upgrading.
2121

2222
[Full Changelog](https://github.com/pomerium/pomerium/compare/v0.27.0...v0.27.1)
2323

24+
Pomerium v0.27.1 includes a fix to the databroker service API authorization logic. Certain service account tokens from Pomerium Zero or Pomerium Enterprise could grant unintended authorization to the databroker service API. See the [CVE-2024-47616](https://github.com/pomerium/pomerium/security/advisories/GHSA-r7rh-jww5-5fjr) for more information.
25+
2426
### Security
2527

2628
- Additional validation checks for gRPC API authorization. This update resolves a security vulnerability that we believe affects only certain Pomerium Enterprise and Pomerium Zero deployments.

0 commit comments

Comments
 (0)