CVE-2022-31145

    Dashboard / Vulnerabilities / CVE-2022-31145

    CVE-2022-31145

    Published: 13 Jul 2022Last Modified: 12 Aug 2026

    Summary: Insufficient AccessToken Expiration Check in FlyteAdmin

    Details: FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. In versions 1.1.30 and prior, authenticated users using an external identity provider can continue to use Access Tokens and ID Tokens even after they expire. Users who use FlyteAdmin as the OAuth2 Authorization Server are unaffected by this issue. A patch is available on the `master` branch of the repository. As a workaround, rotating signing keys immediately will invalidate all open sessions and force all users to attempt to obtain new tokens. Those who use this workaround should continue to rotate keys until FlyteAdmin has been upgraded and hide FlyteAdmin deployment ingress URL from the internet.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    v1.1.19
    v1.1.30
    v1.1.29
    v1.1.28
    v1.1.27
    v1.1.26
    v1.1.23
    v1.1.25
    v1.1.24
    v1.1.22
    v1.1.21
    v1.1.20
    v1.1.18
    v1.1.17
    v1.1.16
    v1.1.15
    v1.1.14
    v1.1.13
    v1.1.12
    v1.1.11
    v1.1.10
    v1.1.9
    v1.1.8
    v1.1.7
    v1.1.6
    v1.1.5
    v1.1.4
    v1.1.3
    v1.1.2
    v1.1.1
    v1.1.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2022-31145 | CVE-DB