Vulnerabilities > Pingidentity > Pingfederate > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-02-06 | CVE-2023-40545 | Missing Authentication for Critical Function vulnerability in Pingidentity Pingfederate 11.3.0 Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests. | 9.8 |
2023-10-25 | CVE-2023-37283 | Improper Authentication vulnerability in Pingidentity Pingfederate Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter | 9.8 |
2021-09-27 | CVE-2021-40329 | Unspecified vulnerability in Pingidentity Pingfederate The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management. | 9.8 |