Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gqc6-p5c3-q963

Опубликовано: 25 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to exploit this vulnerability to register their own MFA device if they have knowledge of a victim user's first factor credentials.

PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to exploit this vulnerability to register their own MFA device if they have knowledge of a victim user's first factor credentials.

EPSS

Процентиль: 35%
0.00145
Низкий

7.3 High

CVSS3

Дефекты

CWE-288
CWE-306

Связанные уязвимости

CVSS3: 7.3
nvd
больше 2 лет назад

PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to exploit this vulnerability to register their own MFA device if they have knowledge of a victim user's first factor credentials.

EPSS

Процентиль: 35%
0.00145
Низкий

7.3 High

CVSS3

Дефекты

CWE-288
CWE-306