Database/Control plane, storage & DevOps
FlyteAdmin (external IdP access token / ID token expiration check): FlyteAdmin does not enforce expiry on access and ID
Impact
FlyteAdmin does not enforce expiry on access and ID tokens issued by an external identity provider, so a token stays usable after the user's session should have ended. Offboarded users and stolen tokens keep working, letting someone launch and inspect workflows on the cluster long after their access was supposed to be revoked.
Who can reach it
Anyone holding an expired but otherwise valid token from the external IdP, including a token pulled from a browser, a CI log or a laptop after offboarding. Deployments using flyteadmin itself as the OAuth2 authorization server are unaffected.
What to do
Upgrade FlyteAdmin to 1.1.30 or later and restart it. Until the upgrade lands, rotate the signing keys repeatedly - each rotation invalidates all open sessions and forces re-authentication, which is the only way to expire the outstanding tokens.
References
Related entries
- HashiCorp Consul: Internal RPC endpoint does not check multiple SAN URIs in a CSRCVE-2022-40716 · HashiCorp ConsulMedium
- AMD IOMMU - not re-initialized during DRTM (AMD-SB-3003): The IOMMU is not re-initialized during a Dynamic Root ofCVE-2023-20591 · AMD IOMMU - not re-initialized during DRTM (AMD-SB-3003)Medium
- Netdata: Agent MACHINE GUID is readable and reusableCVE-2023-22497 · NetdataMedium
- Apache Guacamole: Miscalculated instruction lengths during the Guacamole handshakeCVE-2023-30575 · Apache GuacamoleMedium
- Elasticsearch: Crafted _search query stringCVE-2023-31419 · ElasticsearchMedium
- Argo CD: repo-server extracts a user-controlled tar.gz without size validationCVE-2023-40584 · Argo CDMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.