MEDIUM
PingFederate Password Reset via Authentication API Mishandling
Published May 2, 2022
6.5
MEDIUMCVSS 3.1
EPSS 0.61%
Description
When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.
Affected products
-
- Version 10.0StatusaffectedConstraints<=10.0.12
- Version 10.1StatusaffectedConstraints<=10.1.9
- Version 10.2StatusaffectedConstraints<=10.2.7
- Version 10.3StatusaffectedConstraints<=10.3.4
- Version 11.0StatusaffectedConstraints<=11.0
- Version 9.3StatusaffectedConstraints<=9.3.3P16
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Ping Identity | PingFederate | n/a |
|
OR
- ≥ 9.3.0 · < 9.3.3
- ≥ 10.0.0 · < 10.0.12
- ≥ 10.1.0 · < 10.1.9
- ≥ 10.2.0 · < 10.2.7
- ≥ 10.3.0 · < 10.3.4
- 9.3.3
- 11.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (2)
- https://docs.pingidentity.com/bundle/pingfederate-110/page/spk1642790928508.html x_refsource_MISCRelease NotesVendor Advisory
- https://www.pingidentity.com/en/resources/downloads/pingfederate.html x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://docs.pingidentity.com/bundle/pingfederate-110/page/spk1642790928508.html | x_refsource_MISCRelease NotesVendor Advisory | |
| https://www.pingidentity.com/en/resources/downloads/pingfederate.html | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Ping Identity
Published May 2, 2022
Updated Aug 3, 2024
Reserved Jan 19, 2022
Link CVE-2022-23722
CISA Vulnrichment
Updated n/a