CVE-2022-31677

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/08/2022
Last modified:
07/09/2022

Description

An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially use their access token to continue their session beyond what proper use of their refresh token might allow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:pinniped:*:*:*:*:*:*:*:* 0.3.0 (including) 0.19.0 (excluding)