Impact
A vulnerability in VMware Pinniped Supervisor allows an attacker who can edit a group’s distinguished name in Active Directory to inject LDAP search parameters, causing the modified group to be returned in the user’s search results. Because Pinniped maps Active Directory groups to Kubernetes cluster roles, the attacker can obtain privileges that exceed those intended for the associated AD identity.
Affected Systems
The flaw is present only in VMware Pinniped Supervisor versions 0.11.0 through 0.46.0 inclusive. The vulnerability applies when the server is running with an ActiveDirectoryIdentityProvider resource that has the groupName setting empty; the fix was introduced in version 0.47.0.
Risk and Exploitability
The CVSS score of 3.8 indicates low severity, and the EPSS score of less than 1 % indicates a very low probability of exploitation. The vulnerability can be exploited only if the attacker can edit the DN of a group they belong to, can provide the password of an AD user in that group, and the group search configuration allows the altered DN to be returned. Because of these strict prerequisites, the overall risk to an environment is limited, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment