CVE-2022-22975 Information
Jun 07, 2022
cve
Description
An issue was discovered in the Pinniped Supervisor with either LADPIdentityProvider or ActiveDirectoryIdentityProvider resources. An attack would involve the malicious user changing the common name (CN) of their user entry on the LDAP or AD server to include special characters which could be used to perform LDAP query injection on the Supervisor’s LDAP query which determines their Kubernetes group membership.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Reference
https://github.com/vmware-tanzu/pinniped/security/advisories/GHSA-hvrf-5hhv-4348
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
6.6
Share on: