PingOne MFA Integration Kit是Ping Identity的一个集成工具包,旨在帮助开发者将多因素认证(Multi-Factor Authentication, MFA)功能集成到他们的应用程序或服务中。 PingOne MFA Integration Kit 2.3.1之前版本存在安全漏洞,该漏洞源于可能允许新的MFA设备无需进行第二因素身份验证就可以与目标用户帐户配对。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Ping Identity | PingOne MFA Integration Kit for PingFederate | 0 ~ 2.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-22377 | 5.3 MEDIUM | PingFederate Runtime Node Path Traversal |
| CVE-2024-21832 | 3.5 LOW | PingFederate REST API Data Store Injection |
| CVE-2024-22477 | 1.8 LOW | PingFederate OIDC Policy Management Editor Cross-Site Scripting |
| CVE-2023-40702 | PingOne MFA Integration Kit MFA bypass |
No comments yet