The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET requests.
2023-04-25T19:15:10.383
2024-11-21T07:21:56.407
Modified
CVSSv3.1: 6.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pingidentity | pingfederate | ≤ 10.3.11 | Yes |
Application | pingidentity | pingfederate | ≤ 11.0.6 | Yes |
Application | pingidentity | pingfederate | ≤ 11.1.5 | Yes |
Application | pingidentity | pingfederate | ≤ 11.2.2 | Yes |