cbcvebase.
CVE-2022-31677
published 2022-08-29

CVE-2022-31677: An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticating to Kubernetes clusters via the…

PriorityP426medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.38%
30.3th percentile
An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially use their access token to continue their session beyond what proper use of their refresh token might allow.

Affected

1 ranges
VendorProductVersion rangeFixed in
vmwarepinniped>= 0.3.0 < 0.19.00.19.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.