Product:

Pingfederate

(Pingidentity)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 14
Date Id Summary Products Score Patch Annotated
2024-07-09 CVE-2024-22377 The deploy directory in PingFederate runtime nodes is reachable to unauthorized users. Pingfederate 5.3
2024-07-09 CVE-2024-22477 A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained to admin console users only. Pingfederate 4.3
2024-02-06 CVE-2023-40545 Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests. Pingfederate 9.8
2023-10-25 CVE-2023-37283 Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter Pingfederate 9.8