CVE-2022-31677

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-31677
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-31677.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-31677
Aliases
Related
Published
2022-08-29T15:15:10Z
Modified
2025-02-19T03:27:37.169011Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially use their access token to continue their session beyond what proper use of their refresh token might allow.

References

Affected packages

Git / github.com/vmware-tanzu/pinniped

Affected ranges

Type
GIT
Repo
https://github.com/vmware-tanzu/pinniped
Events

Affected versions

v0.*

v0.10.0
v0.11.0
v0.12.0
v0.13.0
v0.14.0
v0.15.0
v0.16.0
v0.17.0
v0.18.0
v0.3.0
v0.4.0
v0.4.1
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v0.9.0
v0.9.1
v0.9.2