Ping Identity PingFederate PingOne MFA Integration Kit是Ping Identity的该集成工具包允许PingFederate使用 PingOne MFA服务进行多因素身份验证 (MFA)。 Ping Identity PingFederate PingOne MFA Integration Kit 2.3.1之前版本存在安全漏洞,该漏洞源于通过配置skipMFA操作可以使用目标用户的身份进行身份验证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Ping Identity | PingOne MFA Integration Kit for PingFederate | 0 ~ 2.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-22377 | 5.3 MEDIUM | PingFederate Runtime Node Path Traversal |
| CVE-2024-21832 | 3.5 LOW | PingFederate REST API Data Store Injection |
| CVE-2024-22477 | 1.8 LOW | PingFederate OIDC Policy Management Editor Cross-Site Scripting |
| CVE-2023-40356 | PingOne MFA Integration Kit MFA bypass |
No comments yet