Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-42cf-jg8h-gxrv

Опубликовано: 04 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6

Описание

The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The server advances the authentication state without verifying the OTP, thereby bypassing multi-factor authentication.

The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The server advances the authentication state without verifying the OTP, thereby bypassing multi-factor authentication.

EPSS

Процентиль: 29%
0.00106
Низкий

8.6 High

CVSS4

Дефекты

CWE-306

Связанные уязвимости

nvd
2 месяца назад

The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The server advances the authentication state without verifying the OTP, thereby bypassing multi-factor authentication.

EPSS

Процентиль: 29%
0.00106
Низкий

8.6 High

CVSS4

Дефекты

CWE-306