VMware Pinniped
cpe:2.3:a:vmware:pinniped:*:*:*:*:*:*:*
- >= v0.11.0, <= v0.46.0
A privilege escalation vulnerability has been identified in Pinniped Supervisor versions 0.11.0 through 0.46.0, inclusive. This issue arises when the Pinniped Supervisor is configured with an Active Directory Identity Provider and the group name attribute is left empty. Under these conditions, an attacker with knowledge of an Active Directory user's password and the ability to edit group distinguished names could manipulate group entries to gain elevated permissions in Kubernetes clusters.
Exploitation of this vulnerability could allow an authenticated user to gain elevated permissions in Kubernetes clusters, potentially leading to unauthorized access or modifications within the cluster.
Users should upgrade to Pinniped Supervisor version 0.47.0 or later. For those using an Active Directory Identity Provider, it is also recommended to configure the group name attribute to a non-empty value. Additionally, preventing users from editing Active Directory LDAP group entries can mitigate this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.