Vulnerabilities > Pingidentity > Pingfederate > 11.3.0

DATE CVE VULNERABILITY TITLE RISK
2024-07-09 CVE-2024-22377 Path Traversal vulnerability in Pingidentity Pingfederate
The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.
network
low complexity
pingidentity CWE-22
5.3
2024-07-09 CVE-2024-22477 Cross-site Scripting vulnerability in Pingidentity Pingfederate
A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor.
low complexity
pingidentity CWE-79
4.3
2024-02-06 CVE-2023-40545 Missing Authentication for Critical Function vulnerability in Pingidentity Pingfederate 11.3.0
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.
network
low complexity
pingidentity CWE-306
critical
9.8
2023-10-25 CVE-2023-34085 Unspecified vulnerability in Pingidentity Pingfederate
When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request
network
low complexity
pingidentity
4.3
2023-10-25 CVE-2023-37283 Improper Authentication vulnerability in Pingidentity Pingfederate
Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter
network
low complexity
pingidentity CWE-287
critical
9.8
2023-10-25 CVE-2023-39219 Resource Exhaustion vulnerability in Pingidentity Pingfederate
PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests
network
low complexity
pingidentity CWE-400
7.5