Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redirecting an authentication flow to a target user. To exploit the vulnerability, must have compromised user credentials.
2022-05-04T17:15:08.970
2024-11-21T06:49:11.240
Modified
CVSSv3.1: 6.4 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:N
8.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pingidentity | pingid_integration_for_windows_login | < 2.4.2 | Yes |