PT-2022-3916 · Unknown · Pinniped Supervisor

Cfryanr

·

Published

2022-05-11

·

Updated

2024-03-06

·

CVE-2022-22975

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Pinniped Supervisor (affected versions not specified)
Description An issue was discovered in the Pinniped Supervisor with either LADPIdentityProvider or ActiveDirectoryIdentityProvider resources. The issue allows an attack where a malicious user changes the common name (CN) of their user entry on the LDAP or AD server to include special characters. These special characters could be used to perform LDAP query injection on the Supervisor's LDAP query, which determines their Kubernetes group membership.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Special Elements Injection

Weakness Enumeration

Related Identifiers

BDU:2022-04734
BIT-PINNIPED-2022-22975
CVE-2022-22975
GHSA-HVRF-5HHV-4348

Affected Products

Pinniped Supervisor