An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially use their access token to continue their session beyond what proper use of their refresh token might allow.
References
| Link | Resource |
|---|---|
| https://github.com/vmware-tanzu/pinniped/security/advisories/GHSA-rp4v-hhm6-rcv9 | Third Party Advisory |
Configurations
Information
Published : 2022-08-29 08:15
Updated : 2022-09-07 11:41
NVD link : CVE-2022-31677
Mitre link : CVE-2022-31677
JSON object : View
CWE
CWE-613
Insufficient Session Expiration
Products Affected
vmware
- pinniped


