Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter
2023-10-25T18:17:28.270
2024-11-21T08:11:23.580
Modified
CVSSv3.1: 8.1 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pingidentity | pingfederate | ≤ 10.3.12 | Yes |
Application | pingidentity | pingfederate | ≤ 11.1.7 | Yes |
Application | pingidentity | pingfederate | ≤ 11.2.6 | Yes |
Application | pingidentity | pingfederate | 11.3.0 | Yes |