PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amounts of sensitive environmental and application information.
2022-09-30T15:15:09.360
2024-11-21T06:49:11.507
Modified
CVSSv3.1: 5.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pingidentity | pingcentral | < 1.8.4 | Yes |
Application | pingidentity | pingcentral | < 1.9.3 | Yes |