cbcvebase.

Vmware Pinniped vulnerabilities

3 known vulnerabilities affecting vmware/pinniped.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2LOW1

Vulnerabilities

Page 1 of 1
CVE-2022-22975P4MEDIUMCVSS 6.6≥ 0.9.0, < 0.17.0vPinniped versions before v0.17.02022-05-11
CVE-2022-22975 [MEDIUM] CWE-74 CVE-2022-22975: An issue was discovered in the Pinniped Supervisor with either LADPIdentityProvider or ActiveDirecto An issue was discovered in the Pinniped Supervisor with either LADPIdentityProvider or ActiveDirectoryIdentityProvider resources. An attack would involve the malicious user changing the common name (CN) of their user entry on the LDAP or AD server to include special characters, which could be used to perform LDAP query injection on the Supervisor's L
nvd
CVE-2022-31677P4MEDIUMCVSS 5.4≥ 0.3.0, < 0.19.02022-08-29
CVE-2022-31677 [MEDIUM] CWE-613 CVE-2022-31677: An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially use their access token to continue their session beyond what proper use of their refresh token might allow.
nvd
CVE-2026-59269P4LOWCVSS 3.8≥ 0.11.0, ≤ 0.46.02026-07-09
CVE-2026-59269 [LOW] CWE-20 CVE-2026-59269: A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elev A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in the clusters, only if all the following conditions were true: the Pinniped Supervisor server is running with an ActiveDirectoryIdentityProvider resource configured; the ActiveDirectoryIdentityProvider.spec.groupSearch.attributes.groupN
nvd
Vmware Pinniped vulnerabilities | cvebase