GHSA-rp4v-hhm6-rcv9
MODERATECVE-2022-31677A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially use their access token to continue their session beyond what proper use of their refresh token might allow.
- Affected
- >= 0.3.0, < 0.19.0
- Fixed in
- 0.19.0
- Weakness
- CWE-613
- Published
- 2022-09-01
- Source
- github