Vulnerabilities > Pingidentity > Pingfederate > 11.3.1

DATE CVE VULNERABILITY TITLE RISK
2024-07-09 CVE-2024-22377 Path Traversal vulnerability in Pingidentity Pingfederate
The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.
network
low complexity
pingidentity CWE-22
5.3
2024-07-09 CVE-2024-22477 Cross-site Scripting vulnerability in Pingidentity Pingfederate
A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor.
low complexity
pingidentity CWE-79
4.3