漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties file
Vulnerability Description
PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties file. An IT administrator could mistakenly deploy administrator privileged PingID API credentials, such as those typically used by PingFederate, into PingID Windows Login user endpoints. Using sensitive full permissions properties file outside of a privileged trust boundary leads to an increased risk of exposure or discovery, and an attacker could leverage these credentials to perform administrative actions against PingID APIs or endpoints.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
特权API的不正确使用
Vulnerability Title
Ping Identity Windows PingId 安全漏洞
Vulnerability Description
Ping Identity Windows PingId是美国Ping Identity的一款可以为应用程序提供安全保障的软件。 Ping Identity Windows PingId 2.8 之前的版本存在安全漏洞,该漏洞源于IT管理员可能会错误地将管理员特权 PingID API 凭据(例如 PingFederate 通常使用的凭据)部署到 PingID Windows 登录用户端点。
CVSS Information
N/A
Vulnerability Type
N/A