← Back

CVE-2022-22975

nvd nist
Published: May 11, 2022Modified: Jun 17, 2026

JSON object

Loading...
6.6
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.7 / Impact: 5.9
Source: NVD

Description

An issue was discovered in the Pinniped Supervisor with either LADPIdentityProvider or ActiveDirectoryIdentityProvider resources. An attack would involve the malicious user changing the common name (CN) of their user entry on the LDAP or AD server to include special characters, which could be used to perform LDAP query injection on the Supervisor's LDAP query which determines their Kubernetes group membership.

Affected (1)

Products: Vmware: Pinniped
1 product
Pinniped
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 0.9.0 to 0.17.0

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.