CVE-2022-31677
29.08.2022, 15:15
An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially use their access token to continue their session beyond what proper use of their refresh token might allow.Enginsight
Vendor | Product | Version |
---|---|---|
vmware | pinniped | 0.3.0 ≤ 𝑥 < 0.19.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration