BIT-pinniped-2022-31677

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/pinniped/BIT-pinniped-2022-31677.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-pinniped-2022-31677
Aliases
Published
2024-03-06T11:01:40.783Z
Modified
2024-08-21T16:28:54.949881Z
Summary
[none]
Details

An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially use their access token to continue their session beyond what proper use of their refresh token might allow.

Database specific
{
    "cpes": [
        "cpe:2.3:a:vmware:pinniped:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / pinniped

Package

Name
pinniped
Purl
pkg:bitnami/pinniped

Severity

  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0.3.0
Fixed
0.19.0