📦 Pingfederate

by Pingidentity

🔍 What is Pingfederate?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-40545

HIGH CVSS 8.8 Feb 6, 2024

This vulnerability allows attackers to bypass authentication in PingFederate OAuth2 clients using client_secret_jwt authentication. Attackers can send specially crafted requests to gain unauthorized a...

CVE-2023-37283

HIGH CVSS 8.1 Oct 25, 2023

This vulnerability allows authentication bypass in PingFederate's Identifier First Adapter when configured in a specific, non-recommended way. Attackers could potentially gain unauthorized access to p...

CVE-2022-40722

HIGH CVSS 7.7 Apr 25, 2023

This vulnerability allows attackers to bypass offline multi-factor authentication (MFA) in PingID Adapter for PingFederate through pre-computed dictionary attacks targeting RSA padding misconfiguratio...

CVE-2024-22377

MEDIUM CVSS 5.3 Jul 9, 2024

This vulnerability allows unauthorized users to access the deploy directory on PingFederate runtime nodes, potentially exposing sensitive configuration files. It affects organizations running vulnerab...