CVE-2022-31145Exploit(flyte / flyteadmin)

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for flyte flyteadmin systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. In versions 1.1.30 and prior, authenticated users using an external identity provider can continue to use Access Tokens and ID Tokens even after they expire. Users who use FlyteAdmin as the OAuth2 Authorization Server are unaffected by this issue. A patch is available on the `master` branch of the repository. As a workaround, rotating signing keys immediately will invalidate all open sessions and force all users to attempt to obtain new tokens. Those who use this workaround should continue to rotate keys until FlyteAdmin has been upgraded and hide FlyteAdmin deployment ingress URL from the internet.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-613

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flyteadmin

Threat summary

  • Exploit tooling references are present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
flyteadmin

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-24: 1Exploit Tool / Code · 2026-03-24: 103-24
Signal classification1 categories
Exploit
1100.0%
Full discourse1 post
  • Audn AI@audn_ai
    Exploit

    related thing we have seen: during a recent Red Team ops we used Nuclei to spot exposed Grafana panels, then leveraged CVE-2022-31145 with sqlmap to dump configs-still classic attack chain. 🤔

    Post summary

    A Red Team operation used sqlmap to exploit CVE-2022-31145 on exposed Grafana panels and dump configuration data.

    0000036
    119 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflyteflyteadmin---

Explore more